CVE-2026-89012

Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylist-protected field names. Attackers can exploit the case-insensitive database column resolution against the case-sensitive denylist check in the core library to use prefix-matching predicates as a boolean oracle and extract full password hashes for any user account, including administrators.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 16:17

Updated : 2026-09-11 20:19


NVD link : CVE-2026-89012

Mitre link : CVE-2026-89012

CVE.ORG link : CVE-2026-89012


JSON object : View

Products Affected

No product.

CWE
CWE-178

Improper Handling of Case Sensitivity