No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No reference.
Tue, 18 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Tue, 18 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dolibarr contains an authorization bypass vulnerability in the clonetasks mass action that allows authenticated users with project creation permissions to clone tasks into private projects they are not authorized to access. An inverted boolean condition in the private-project membership check within actions_massactions.inc.php causes the authorization flag to be set for unauthorized users, allowing attackers to supply a user-controlled projectid POST parameter to create task records in any private project. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| Title | Authorization Bypass via Inverted Boolean in clonetasks Mass Action in Dolibarr ERP/CRM | |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Tue, 18 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dolibarr
Dolibarr erp Crm |
|
| Vendors & Products |
Dolibarr
Dolibarr erp Crm |
Tue, 18 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dolibarr contains an authorization bypass vulnerability in the clonetasks mass action that allows authenticated users with project creation permissions to clone tasks into private projects they are not authorized to access. An inverted boolean condition in the private-project membership check within actions_massactions.inc.php causes the authorization flag to be set for unauthorized users, allowing attackers to supply a user-controlled projectid POST parameter to create task records in any private project. | |
| Title | Authorization Bypass via Inverted Boolean in clonetasks Mass Action in Dolibarr ERP/CRM | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: REJECTED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T15:34:08.578Z
Reserved: 2026-08-13T15:15:54.512Z
Link: CVE-2026-73692
No data.
Status : Rejected
Published: 2026-08-18T14:18:07.553
Modified: 2026-08-18T16:18:17.430
Link: CVE-2026-73692
No data.
OpenCVE Enrichment
Updated: 2026-08-18T14:45:03Z
No weakness.