MEDIUMVulnerability
CVE-2026-82633
Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users. Attackers can call GET /users/{id}/groups with arbitrary user identifiers to access group names, entity associations, and private notes across tenant boundaries.
Properties
- severity
- MEDIUM
- score
- 4.3
- epss_score
- 0.00211
- cve_id
- CVE-2026-82633
- signal_observed_at
- 2026-09-15T21:12:48+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- published_at
- 2026-08-30T13:16:56.613
- last_modified
- 2026-09-10T15:53:23.707
- epss_percentile
- 0.11471
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Missing Authorization
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph