AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-19350

MEDIUM · CVSS 6.3 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-09 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The TakePOS Module in Dolibarr ERP versions up to 23.0.3 is vulnerable due to a missing authorization in the invoice.php file, allowing remote attackers to exploit this weakness. This could lead to unauthorized access and manipulation of invoices, potentially compromising sensitive financial data. Organizations using Dolibarr ERP should prioritize applying the provided patch to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19350
Severity
MEDIUM
CVSS
6.3
EPSS
0.35%

Original NVD Description

A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is 8992ce8704da947b6abe7b65a6fe59aed736bb81. It is advisable to implement a patch to correct this issue.