Dolibarr - LFI (CVE-2026-34036)
Description
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc parameter and exploiting a fail-open logic flaw in the core access control function restrictedArea(), an authenticated user with no specific privileges can read the contents of arbitrary non-PHP files on the server (such as .env, .htaccess, configuration backups, or logs…). At time of publication, there are no publicly available patches.
psychologyCrowdSec Analysis
CVE-2026-34036 is a high-severity local file inclusion vulnerability in Dolibarr 22.0.4 and earlier, affecting the core AJAX endpoint /core/ajax/selectobject.php. An authenticated user without specific privileges can exploit flawed access-control logic to read arbitrary non-PHP files, including environment files, configuration backups, and server logs, potentially exposing sensitive credentials and operational data.
CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.
CrowdSec has not observed any significant exploitation activity targeting CVE-2026-34036 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.
Authenticated attackers target /core/ajax/selectobject.php and manipulate the objectdesc parameter with traversal-style file references such as A:includes/.htaccess:0 to trigger local file inclusion and retrieve sensitive non-PHP files. Detection should correlate the request with a preceding Dolibarr login flow and responses containing .htaccess directives such as FilesMatch and SetHandler.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2026-03-31 |
| Rule Released | 2026-08-03 |