CVE-2026-58376
HIGHDolibarr - SQL Injection via sqlfilters Parameter in Multiple REST API List Endpoints
Title source: cnaDescription
Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrary database contents by supplying malicious values to the sqlfilters query parameter in the setup dictionary and multicurrencies REST API endpoints. The affected endpoints in api_setup.class.php and api_multicurrencies.class.php validate sqlfilters only for balanced parentheses and rewrite matched triplets, allowing text placed outside the expected shape such as an appended UNION SELECT to be concatenated into the SQL WHERE clause unmodified, enabling retrieval of sensitive data including password hashes and API keys.
References (4)
Core 4
Core References
Exploit exploit
technical-description
Researcher Disclosure
https://github.com/Dolibarr/dolibarr/issues/38768
Patch patch
Fix Commit
https://github.com/Dolibarr/dolibarr/commit/14db36e8486ef725b0d493d97abb2950a54358d3
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/dolibarr-sql-injection-via-sqlfilters-parameter-in-multiple-rest-api-list-endpoints
Scores
CVSS v3
7.6
EPSS
0.0022
EPSS Percentile
12.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-89
Status
published
Products (2)
Dolibarr/dolibarr
< 23.0.3
Dolibarr/dolibarr
14db36e8486ef725b0d493d97abb2950a54358d3
Published
Jun 30, 2026
Tracked Since
Jun 30, 2026