CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-34036Public Exploit

Dolibarr - LFI (CVE-2026-34036)

PublishedMar 31, 2026
First SeenN/A
Last Seen
Reported
CVSS6.5
enterprise_softwarephp

Description

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc parameter and exploiting a fail-open logic flaw in the core access control function restrictedArea(), an authenticated user with no specific privileges can read the contents of arbitrary non-PHP files on the server (such as .env, .htaccess, configuration backups, or logs…). At time of publication, there are no publicly available patches.

psychologyCrowdSec Analysis

CVE-2026-34036 is a high-severity local file inclusion vulnerability in Dolibarr 22.0.4 and earlier, affecting the core AJAX endpoint /core/ajax/selectobject.php. An authenticated user without specific privileges can exploit flawed access-control logic to read arbitrary non-PHP files, including environment files, configuration backups, and server logs, potentially exposing sensitive credentials and operational data.

CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-34036 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Authenticated attackers target /core/ajax/selectobject.php and manipulate the objectdesc parameter with traversal-style file references such as A:includes/.htaccess:0 to trigger local file inclusion and retrieve sensitive non-PHP files. Detection should correlate the request with a preceding Dolibarr login flow and responses containing .htaccess directives such as FilesMatch and SetHandler.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-03-31
Rule Released2026-08-03

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.