# CVE-2026-89013: Dolibarr - Information Disclosure

> Live exploitation tracking for CVE-2026-89013 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-89013

## Key facts

- **Exploitation phase:** Insufficient Data. Not enough CrowdSec telemetry data is available to confidently assess how this vulnerability is exploited in the wild.
- **CVSS score:** 8.7
- **Public exploit available:** Yes
- **Affected products:** Dolibarr
- **Weaknesses:** CWE-863 (Incorrect Authorization)
- **Tags:** enterprise_software, web_application

## Description

Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining access to application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.

## CrowdSec analysis

[CVE-2026-89013](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-89013) is a high-severity authorization bypass vulnerability in Dolibarr 23.0.4 before 24.0.1 that allows unauthenticated attackers to read arbitrary files through document storage endpoints by supplying a crafted `hashp` parameter. Successful exploitation can expose application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.

CrowdSec has been tracking this vulnerability and its exploits since 5th of October 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-89013 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Attackers target Dolibarr’s `/document.php` endpoint by supplying `hashp=shared` to bypass authorization checks. They abuse the `modulepart` and `file` parameters to request arbitrary files from managed media directories without authentication.

## Timeline

- 2026-09-11: CVE Published. CVE-2026-89013 is published to NVD.
- 2026-10-05: Rule Released. CrowdSec releases a rule to detect CVE-2026-89013 exploitation attempts against the CrowdSec Network.

## References

- https://www.vulncheck.com/advisories/dolibarr-authorization-bypass-via-hashp-parameter-in-document-php
- https://github.com/Dolibarr/dolibarr/releases/tag/24.0.1
- https://github.com/Dolibarr/dolibarr/commit/cd05688dbed8a4af6eef32faf4fc1e823a37bce9
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-89013.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-89013) follows observed exploitation activity for CVE-2026-89013. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
