CVE-2026-89012 affects Dolibarr 24.0.0 before 24.0.1. The sqlfilters API query parameter applies a case-sensitive denylist to protected field names, while the underlying database resolves column names case-insensitively. An authenticated attacker can submit uppercase or mixed-case variants of denied field names to bypass filtering. Prefix-matching predicates can then be used as a boolean oracle to infer protected field values, including password hashes.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This two-file standalone Python repository contains an operational authenticated data-disclosure exploit for Dolibarr 24.0.0, plus documentation. CVE-2026-89012 is described as a bypass in forgeSQLFromUniversalSearchCriteria(): the filter parser permits uppercase letters, but checks forbidden field names with case-sensitive PHP in_array(). Supplying an uppercase identifier such as t.PASS_CRYPTED avoids a lowercase denylist entry while case-insensitive SQL resolution still accesses the protected column. The Python entry point uses only the standard library (argparse, urllib, ssl, JSON, and concurrent futures), supports proxies, TLS-verification disabling, request timeouts, configurable worker count, custom target paths, and output files. Its check command performs a low-request validation; users lists readable users; dump performs parallel prefix-LIKE probes using a selectable bcrypt, hexadecimal, alphanumeric, or digit charset to recover sensitive values. The default target is the REST users endpoint and the default field is PASS_CRYPTED. It is not merely a detector because it includes automated credential/secret extraction functionality. No fixed victim host, IP, or command-and-control endpoint is embedded; the operator supplies the Dolibarr base URL and API key at runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.