Description

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc parameter and exploiting a fail-open logic flaw in the core access control function restrictedArea(), an authenticated user with no specific privileges can read the contents of arbitrary non-PHP files on the server (such as .env, .htaccess, configuration backups, or logs…). At time of publication, there are no publicly available patches.

INFO

Published Date :

2026-03-31T01:39:38.178Z

Last Modified :

2026-03-31T13:57:45.230Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-34036 vulnerability.

Vendors Products
Dolibarr
  • Dolibarr
  • Dolibarr Erp\/crm
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-34036.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact