CVE-2026-71504 · The membership desk that could reset the admin's password
CVSS 8.3 · Mass assignment (CWE-915) · Fixed in Dolibarr 24.0.0
The front desk refuses to change the CEO's password. But the membership clerk's window, which nobody thought to lock will happily do it,
security-research.hashnode.dev6 min read