CVE-2026-58376
Last modified
CVE-2026-58376 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrary database contents by supplying malicious values to the sqlfilters query parameter in the setup dictionary and multicurrencies REST API endpoints. The affected endpoints in api_setup.class.php and api_multicurrencies.class.php validate sqlfilters only for balanced parentheses and rewrite matched triplets, allowing text placed outside the expected shape such as an appended UNION SELECT to be concatenated into the SQL WHERE clause unmodified, enabling retrieval of sensitive data including password hashes and API keys.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrary database contents by supplying malicious values to the sqlfilters query parameter in the setup dictionary and multicurrencies REST API endpoints. The affected endpoints in api_setup.class.php and api_multicurrencies.class.php validate sqlfilters only for balanced parentheses and rewrite matched triplets, allowing text placed outside the expected shape such as an appended UNION SELECT to be concatenated into the SQL WHERE clause unmodified, enabling retrieval of sensitive data including password hashes and API keys.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Dolibarr | dolibarr | <= 23.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-58376?
How severe is CVE-2026-58376?
How do I fix CVE-2026-58376?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-58370Woodpecker before 3.15.0 matches the ApprovalAllowedUsers by…9.2
- CVE-2026-58371SeaweedFS before 4.30 reflects the callback query parameter …3.1
- CVE-2026-58372SeaweedFS before 4.34 contains a path traversal vulnerabilit…8.1
- CVE-2026-58373CVAT before 2.69.0 contains an improper authorization vulner…5.3
- CVE-2026-58374In hostapd before 2.12, a missing bounds check in AP-mode Wi…7.1
- CVE-2026-58375JimuReport through 2.5.0 exposes the POST /jmreport/auto/exp…8.7
- CVE-2026-58377JeecgBoot through 3.9.2 contains a broken access control vul…8.6
- CVE-2026-58378Allwinner H616 TV Box TV98 has ADB enabled and exposed to th…8.8
- CVE-2026-58379A flaw was found in GIMP's Paint Shop Pro (PSP) file format …7.3
- CVE-2026-5838A vulnerability was determined in PHPGurukul News Portal Pro…4.7
- CVE-2026-58380A flaw was found in GIMP's PNM file format parser. When pars…7.8
- CVE-2026-58381A flaw was found in GIMP's PSP file format parser. A double-…6.1
Are you affected by CVE-2026-58376?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
