CVE-2026-7689Disclosure

LOWCVSS 2.9 · LOW

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in Dolibarr ERP CRM up to 23.0.2. This vulnerability affects the function dol_verifyHash in the library htdocs/core/lib/security.lib.php of the component Online Signature Module. The manipulation results in improper verification of cryptographic signature. The attack may be performed from remote. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-03: 4Technical Details · 2026-05-03: 405-03
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    💼 Enterprise ERP Alert: Dolibarr ERP CRM (up to 23.0.2) hit by critical flaws, including improper cryptographic signature verification (CVE-2026-7689) and SQL Injection in Shipments API (CVE-2026-7688). Source: https://vuldb.com/vuln/360859

    Post summary

    Dolibarr ERP CRM versions up to 23.0.2 are affected by two critical vulnerabilities: improper cryptographic signature verification (CVE-2026-7689) and a SQL Injection in the Shipments API (CVE-2026-7688).

    1000023
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7689 A security flaw has been discovered in Dolibarr ERP CRM up to 23.0.2. This vulnerability affects the function dol_verifyHash in the library htdocs/core/lib/security.lib… https://www.cve.org/CVERecord?id=CVE-2026-7689

    Post summary

    The post announces discovery of CVE-2026-7689, a flaw in Dolibarr's dol_verifyHash function up to version 23.0.2, without providing PoC, exploit, or patch details.

    00010262
    57.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7689 A security flaw has been discovered in Dolibarr ERP CRM up to 23.0.2. This vulnerability affects the function dol_verifyHash in the library htdocs/core/lib/security.lib… https://www.cve.org/CVERecord?id=CVE-2026-7689 ----- Traducción: CVE-2026-7689 Se … http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-7689, a vulnerability in Dolibarr ERP/CRM affecting the dol_verifyHash function in versions up to 23.0.2, without providing exploit, patch, or active exploitation details.

    0000027
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7689 Improper Cryptographic Signature Verification in Dolibarr ERP CRM 23.0.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7689

    Post summary

    The snippet references CVE-2026-7689, an Improper Cryptographic Signature Verification vulnerability in Dolibarr ERP CRM 23.0.2, but provides no additional details on exploitation, patches, or PoC.

    0000057
    4.0K followersView on X

Explore more