📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Technology/Software CRITICAL 1h Global malware Social Media and Consumer Technology HIGH 1h Global botnet Information Technology and IoT HIGH 1h Global vulnerability Enterprise Security, Software Development CRITICAL 2h Global vulnerability Software Development, Artificial Intelligence HIGH 2h Global apt Defense and Military CRITICAL 2h Global vulnerability Networking, Software, Infrastructure HIGH 2h Global phishing Information Technology HIGH 3h Global ransomware Multiple sectors CRITICAL 3h Global malware Multiple sectors CRITICAL 3h Global vulnerability Technology/Software CRITICAL 1h Global malware Social Media and Consumer Technology HIGH 1h Global botnet Information Technology and IoT HIGH 1h Global vulnerability Enterprise Security, Software Development CRITICAL 2h Global vulnerability Software Development, Artificial Intelligence HIGH 2h Global apt Defense and Military CRITICAL 2h Global vulnerability Networking, Software, Infrastructure HIGH 2h Global phishing Information Technology HIGH 3h Global ransomware Multiple sectors CRITICAL 3h Global malware Multiple sectors CRITICAL 3h Global vulnerability Technology/Software CRITICAL 1h Global malware Social Media and Consumer Technology HIGH 1h Global botnet Information Technology and IoT HIGH 1h Global vulnerability Enterprise Security, Software Development CRITICAL 2h Global vulnerability Software Development, Artificial Intelligence HIGH 2h Global apt Defense and Military CRITICAL 2h Global vulnerability Networking, Software, Infrastructure HIGH 2h Global phishing Information Technology HIGH 3h Global ransomware Multiple sectors CRITICAL 3h Global malware Multiple sectors CRITICAL 3h
Vulnerabilities

CVE-2026-11619

Medium
CWE-266 — Weakness Type
Published: Jun 9, 2026  ·  Modified: Jun 9, 2026  ·  Source: NVD
CVSS v3
6.3
🔗 NVD Official
📄 Description (English)

A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy Filemanager. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. Upgrading to version 23.0.3 is sufficient to resolve this issue. The identifier of the patch is f1b2dd6481e22cacb561d29ffdcd3a50b618479d. Upgrading the affected component is advised.

🤖 AI Executive Summary

Dolibarr ERP CRM versions up to 23.0.2 contain an improper authorization vulnerability in the Legacy Filemanager component that allows remote attackers to bypass access controls. The vulnerability affects the config.inc.php file and has a publicly available exploit, though patch availability is currently limited. Organizations using Dolibarr should immediately implement compensating controls and plan for urgent patching.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Jun 9, 2026 07:30
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi organizations using Dolibarr ERP CRM, particularly in: (1) Government agencies and municipalities relying on Dolibarr for document and resource management; (2) Small to medium-sized enterprises (SMEs) in retail, manufacturing, and services sectors; (3) Healthcare facilities using Dolibarr for administrative and inventory management; (4) Educational institutions managing institutional resources. The improper authorization flaw could allow unauthorized access to sensitive business documents, financial records, and confidential data, directly impacting compliance with NCA ECC 2024 and SAMA CSF requirements for access control and data protection.
🏢 Affected Saudi Sectors
Government and Public Administration Small and Medium Enterprises (SMEs) Healthcare and Medical Facilities Education and Universities Retail and E-commerce Manufacturing Professional Services
⚖️ Saudi Risk Score (AI)
6.8
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all instances of Dolibarr ERP CRM in your environment and document versions (particularly versions ≤23.0.2)
2. Restrict network access to htdocs/core/filemanagerdol/connectors/php/config.inc.php using WAF rules or firewall ACLs
3. Implement IP whitelisting for administrative access to Dolibarr instances
4. Review access logs for suspicious activity targeting the Legacy Filemanager component

PATCHING GUIDANCE:
1. Upgrade to Dolibarr version 23.0.3 or later immediately when available
2. Apply patch f1b2dd6481e22cacb561d29ffdcd3a50b618479d from official Dolibarr repository
3. Test patches in non-production environment before deployment
4. Maintain backup before patching

COMPENSATING CONTROLS (until patch available):
1. Disable Legacy Filemanager component if not actively used
2. Implement reverse proxy authentication (e.g., nginx/Apache) requiring additional authentication
3. Deploy Web Application Firewall (WAF) rules to block suspicious requests to config.inc.php
4. Implement file integrity monitoring (FIM) on affected PHP files
5. Restrict PHP execution permissions on filemanagerdol directory

DETECTION RULES:
1. Monitor HTTP requests to /htdocs/core/filemanagerdol/connectors/php/config.inc.php with unusual parameters
2. Alert on unauthorized file access attempts in Dolibarr logs
3. Track failed authentication attempts followed by successful access to filemanager functions
4. Monitor for privilege escalation patterns in Dolibarr audit logs
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حدد جميع مثيلات Dolibarr ERP CRM في بيئتك وتوثيق الإصدارات (خاصة الإصدارات ≤23.0.2)
2. قيد الوصول إلى الشبكة إلى htdocs/core/filemanagerdol/connectors/php/config.inc.php باستخدام قواعد WAF أو قوائم التحكم في الوصول بجدار الحماية
3. تنفيذ قائمة بيضاء IP للوصول الإداري إلى مثيلات Dolibarr
4. راجع سجلات الوصول للنشاط المريب الموجه نحو مكون Legacy Filemanager

إرشادات التصحيح:
1. قم بالترقية إلى إصدار Dolibarr 23.0.3 أو أحدث فوراً عند توفره
2. تطبيق التصحيح f1b2dd6481e22cacb561d29ffdcd3a50b618479d من مستودع Dolibarr الرسمي
3. اختبر التصحيحات في بيئة غير الإنتاج قبل النشر
4. الحفاظ على النسخة الاحتياطية قبل التصحيح

عناصر التحكم التعويضية (حتى توفر التصحيح):
1. تعطيل مكون Legacy Filemanager إذا لم يكن قيد الاستخدام النشط
2. تنفيذ مصادقة reverse proxy (مثل nginx/Apache) تتطلب مصادقة إضافية
3. نشر قواعد Web Application Firewall (WAF) لحظر الطلبات المريبة إلى config.inc.php
4. تنفيذ مراقبة سلامة الملفات (FIM) على ملفات PHP المتأثرة
5. تقييد أذونات تنفيذ PHP على دليل filemanagerdol

قواعد الكشف:
1. مراقبة طلبات HTTP إلى /htdocs/core/filemanagerdol/connectors/php/config.inc.php بمعاملات غير عادية
2. تنبيه على محاولات الوصول غير المصرح بها للملفات في سجلات Dolibarr
3. تتبع محاولات المصادقة الفاشلة متبوعة بالوصول الناجح إلى وظائف filemanager
4. مراقبة أنماط تصعيد الامتيازات في سجلات تدقيق Dolibarr
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.9.1.1 - Access control policy A.9.2.1 - User registration and de-registration A.9.2.5 - Access rights review A.9.4.3 - Password management A.14.2.1 - Secure development policy
🔵 SAMA CSF
AC-2: Account Management AC-3: Access Enforcement AC-6: Least Privilege SI-4: Information System Monitoring AU-2: Audit Events
🟡 ISO 27001:2022
6.2 - Determine access needs 6.3 - Access control 8.2.3 - Segregation of duties 8.3.2 - User access provisioning 8.3.3 - Management of privileged access rights
🟣 PCI DSS v4.0.1
Requirement 7 - Restrict access to data by business need to know Requirement 8 - Identify and authenticate access to system components
📊 CVSS Score
6.3
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score6.3
CWECWE-266
EPSS0.04%
Exploit No
Patch ✗ No
Published 2026-06-09
Source Feed nvd
Views 1
🇸🇦 Saudi Risk Score
6.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-266
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.