CVE-2026-23500 - Vulnerability Analysis
N/aLast Updated: April 17, 2026
Dolibarr - Remote Code Execution
Published: April 17, 2026Updated: April 17, 2026PoC Available
Overview
Dolibarr < 23.0.0 contains a command injection caused by unsanitized MAIN_ODT_AS_PDF configuration constant concatenated in shell command in odf.php, letting authenticated administrators execute arbitrary OS commands, exploit requires admin privileges.
Severity & Score
Severity: N/a
Impact
Authenticated administrators can execute arbitrary OS commands as the web server user, leading to full remote code execution.
Mitigation
Upgrade to version 23.0.0 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-23500
- Severity
- N/a
- Type
- command_injection
- Status
- new
CWE
- CWE-78
CVSS Metrics
N/A