Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dolibarr contains an authorization bypass vulnerability in the clonetasks mass action that allows authenticated users with project creation permissions to clone tasks into private projects they are not authorized to access. An inverted boolean condition in the private-project membership check within actions_massactions.inc.php causes the authorization flag to be set for unauthorized users, allowing attackers to supply a user-controlled projectid POST parameter to create task records in any private project. | |
| Title | Authorization Bypass via Inverted Boolean in clonetasks Mass Action in Dolibarr ERP/CRM | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T13:39:16.626Z
Reserved: 2026-08-13T15:15:54.512Z
Link: CVE-2026-73692
No data.
Status : Received
Published: 2026-08-18T14:18:07.553
Modified: 2026-08-18T14:18:07.553
Link: CVE-2026-73692
No data.
OpenCVE Enrichment
No data.
-
CWE-863
Incorrect Authorization