{"apiVersion":"1.0","identifier":"CVE-2026-71504","description":"Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. Attackers can supply an arbitrary user account identifier and new password in the request body to overwrite credentials and immediately lock out the legitimate account holder.","publishedAt":"2026-08-24T19:16:49","lastModifiedAt":"2026-08-27T17:19:45","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71504","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","epssProbability":0.00257,"riskScore":0.83,"affectedProduct":"Dolibarr","affectedVersions":"<24.0.0","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-71504","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-71504","en":"https://www.redsauce.net/en/cves/CVE-2026-71504","fr":"https://www.redsauce.net/fr/cves/CVE-2026-71504","pt":"https://www.redsauce.net/pt/cves/CVE-2026-71504","de":"https://www.redsauce.net/de/cves/CVE-2026-71504","sk":"https://www.redsauce.net/sk/cves/CVE-2026-71504","el":"https://www.redsauce.net/el/cves/CVE-2026-71504"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-71504"}}