SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-71506

HIGH · CVSS 8.1 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

An improper authorization vulnerability in the payments REST API delete endpoint of Dolibarr before version 24.0.0 allows authenticated users with invoice-deletion rights to bypass permission checks and permanently delete any payment record. This can lead to significant financial data integrity loss, as attackers can manipulate invoice amounts and erase entries from accounting exports. Organizations using Dolibarr should prioritize patching this vulnerability to safeguard their financial records and prevent unauthorized data manipulation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-71506
Severity
HIGH
CVSS
8.1
EPSS
0.30%

Original NVD Description

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check. Attackers can exploit this misconfigured permission check to zero paid amounts on invoices and remove entries from accounting exports, causing financial data integrity loss.