What is CVE-2026-19350?
A missing authorization vulnerability exists in the `fail` function within `htdocs/takepos/invoice.php` of the TakePOS module in Dolibarr ERP up to version 23.0.3. This allows remote attackers to perform unauthorized actions. Apply the patch `8992ce8704da947b6abe7` immediately.
Azərbaycanca: Dolibarr ERP-nin 23.0.3 versiyasına qədər TakePOS modulunda `htdocs/takepos/invoice.php` faylında yerləşən `fail` funksiyasında çatışmazlıq aşkar edilib. Bu, uzaqdan icazəsiz əməliyyatlara yol aça bilən missing authorization zəifliyidir. Dərhal `8992ce8704da947b6abe7` yaması tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which module of Dolibarr ERP is affected by CVE-2026-19350?
The CVE-2026-19350 vulnerability affects the TakePOS module of Dolibarr ERP.
What is the identifier of the recommended patch for CVE-2026-19350?
The recommended patch for CVE-2026-19350 has the identifier `8992ce8704da947b6abe7`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.