Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users. Attackers can call GET /users/{id}/groups with arbitrary user identifiers to access group names, entity associations, and private notes across tenant boundaries.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 30 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users. Attackers can call GET /users/{id}/groups with arbitrary user identifiers to access group names, entity associations, and private notes across tenant boundaries. | |
| Title | Dolibarr 10.0.0 before 24.0.0 Missing Authorization on REST Users Groups Endpoint | |
| First Time appeared |
Dolibarr
Dolibarr dolibarr Erp\/crm |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dolibarr
Dolibarr dolibarr Erp\/crm |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-30T12:34:51.768Z
Reserved: 2026-08-30T11:59:01.719Z
Link: CVE-2026-82633
No data.
Status : Received
Published: 2026-08-30T13:16:56.613
Modified: 2026-08-30T13:16:56.613
Link: CVE-2026-82633
No data.
OpenCVE Enrichment
Updated: 2026-08-30T13:30:05Z
Weaknesses