Two high-severity vulnerabilities in Dolibarr ERP/CRM allow authenticated administrators to achieve remote code execution through separate application paths. CVE-2026-22666 affects versions before 23.0.2 and stems from the dol_eval_standard() function, which can be abused through computed extrafields and other evaluation paths because forbidden string checks are not properly enforced in whitelist mode and PHP dynamic callable syntax is not detected. The flaw enables arbitrary command execution via eval() and is classified as CWE-95.
A second issue, CVE-2026-23500, affects versions before 23.0.0 and exposes an OS command injection bug in the ODT-to-PDF conversion workflow in odf.php. The MAIN_ODT_AS_PDF configuration constant is concatenated into a shell command passed to exec() without sanitization, allowing an authenticated administrator to inject shell separators and run arbitrary commands as the web server user when generating an ODT template. The vulnerabilities were addressed in Dolibarr 23.0.0 and 23.0.2, underscoring the need for organizations running Dolibarr to upgrade promptly.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
GitHub security advisories received the CVE-2026-23500 record and published references to the advisory and the Dolibarr 23.0.0 release. The CVE describes an authenticated administrator-to-RCE path via unsanitized shell command construction in odf.php.
Dolibarr released version 23.0.0, which fixed an OS command injection vulnerability in odf.php affecting versions prior to 23.0.0. The flaw allowed an authenticated administrator to inject shell commands through the MAIN_ODT_AS_PDF configuration during ODT-to-PDF conversion.
Dolibarr released version 23.0.2 to address CVE-2026-22666, an authenticated remote code execution vulnerability affecting versions before 23.0.2. The bug stemmed from insufficient forbidden-string enforcement and failure to detect PHP dynamic callable syntax in dol_eval_standard().
VulnCheck's disclosure channel received a report for CVE-2026-22666, an authenticated remote code execution flaw in Dolibarr's dol_eval_standard() function. The issue allowed an administrator to bypass validation in whitelist mode and achieve arbitrary code execution via eval().
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.