Answer in brief
CVE-2026-78160 records a Unknown severity vulnerability in Dolibarr ERP User Notes note.php authorization. The current sources do not mark it as known exploited. The current feed maps Dolibarr/ERP (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Dolibarr/ERP (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Dolibarr/ERPgeneric | 18.0.0 || 18.0.1 || 18.0.2 || 18.0.3 || 18.0.4 || 18.0.5 || 18.0.6 || 18.0.7 || 18.0.8 || 18.0.9 || 18.0.10 || 22.0.0 || 22.0.1 || 22.0.2 || 22.0.3 || 22.0.4 || 22.0.5 || 23.0.0 || 23.0.1 || 23.0.2 || 23.0.3 | Not reported |
Published upstream
Aug 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 24, 2026
A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of the component User Notes Handler. The manipulation of the argument ID leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 23.0.4 and 24.0.0 is capable of addressing this issue. The identifier of the patch is 9b5229ef3a9b58d00252d327936b022fb739f149. Upgrading the affected component is advised.
Quoted source text, attributed separately from HOL analysis.