216.73.216.226

CVE-2026-22666

· Published 07/04/2026 13:16 · Modified 07/04/2026 13:20

Labels: CVE-2026-22666 2026-04-07CVE-2026-22666CWE-95[email protected]

Essential information

Published
07/04/2026 13:16
Modified
07/04/2026 13:20
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax. Attackers with administrator privileges can inject malicious payloads through computed extrafields or other evaluation paths using PHP dynamic callable syntax to bypass validation and achieve arbitrary command execution via eval().

NVD status

Status
Undergoing Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
dolibarr / dolibarr cpe:2.3:a:dolibarr:dolibarr:*:<23.0.2>:*:*:*:*:*:*

References