HIGHVulnerability
CVE-2026-71504
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. Attackers can supply an arbitrary user account identifier and new password in the request body to overwrite credentials and immediately lock out the legitimate account holder.
Properties
- severity
- HIGH
- score
- 8.1
- epss_score
- 0.00257
- cve_id
- CVE-2026-71504
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- published_at
- 2026-08-24T19:16:49.670
- last_modified
- 2026-09-08T20:23:49.880
- epss_percentile
- 0.17283
Related Entities (4)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (2)
→[Weakness]Improperly Controlled Modification of Dynamically-Determined Object Attributes
→[Weakness]Missing Authorization
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph