SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85401

MEDIUM · CVSS 6.3 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in the Legacy File Manager component of Dolibarr versions up to 21.0.4, 22.0.5, and 23.0.3, allowing for improper access controls due to a weakness in the file htdocs/core/filemanagerdol/connectors/php/config.inc.php. This flaw can be exploited remotely, potentially leading to unauthorized access. Organizations using affected Dolibarr versions should prioritize upgrading to version 23.0.4 to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85401
Severity
MEDIUM
CVSS
6.3
EPSS
0.25%

Original NVD Description

A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy File Manager. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 23.0.4 can resolve this issue. This patch is called ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec. It is suggested to upgrade the affected component.