# CVE-2026-34036: Dolibarr - LFI

> Live exploitation tracking for CVE-2026-34036 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-34036

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 6.5
- **Public exploit available:** Yes
- **Affected products:** Dolibarr
- **Weaknesses:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
- **Tags:** enterprise_software, php

## Description

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc parameter and exploiting a fail-open logic flaw in the core access control function restrictedArea(), an authenticated user with no specific privileges can read the contents of arbitrary non-PHP files on the server (such as .env, .htaccess, configuration backups, or logs…). At time of publication, there are no publicly available patches.

## CrowdSec analysis

[CVE-2026-34036](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-34036) is a high-severity local file inclusion vulnerability in Dolibarr 22.0.4 and earlier, affecting the core AJAX endpoint `/core/ajax/selectobject.php`. An authenticated user without specific privileges can exploit flawed access-control logic to read arbitrary non-PHP files, including environment files, configuration backups, and server logs, potentially exposing sensitive credentials and operational data.

CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-34036 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Authenticated attackers target `/core/ajax/selectobject.php` and manipulate the `objectdesc` parameter with traversal-style file references such as `A:includes/.htaccess:0` to trigger local file inclusion and retrieve sensitive non-PHP files. Detection should correlate the request with a preceding Dolibarr login flow and responses containing `.htaccess` directives such as `FilesMatch` and `SetHandler`.

## Timeline

- 2026-03-31: CVE Published. CVE-2026-34036 is published to NVD.
- 2026-08-03: Rule Released. CrowdSec releases a rule to detect CVE-2026-34036 exploitation attempts against the CrowdSec Network.

## References

- https://github.com/Dolibarr/dolibarr/security/advisories/GHSA-2mfj-r695-5h9r
- https://github.com/Dolibarr/dolibarr/commit/743c22e57c0b2a017d6b92bec865d71ce6177a6a
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-34036.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-34036) follows observed exploitation activity for CVE-2026-34036. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
