What is CVE-2026-19930?
A remote LDAP injection vulnerability has been identified in Dolibarr up to version 23.0.3, specifically within the 'User Cloning' function of the 'card.php' file. This flaw allows attackers to manipulate the 'ID' argument to inject malicious LDAP queries, potentially compromising the underlying directory service. Users are advised to update to the latest patched version and enforce strict input sanitization.
Azərbaycanca: Dolibarr platformasının 23.0.3-ə qədər versiyalarında, 'User Cloning' komponentindəki 'card.php' faylında LDAP injection zəifliyi aşkar edilib. Bu boşluq uzaqdan hücum edən şəxsə ID arqumentini manipulyasiya edərək LDAP serverinə sorğu yeridə bilməyə imkan verir. İstifadəçilər dərhal ən son versiyaya yeniləməli və giriş validasiyasını gücləndirməlidir.
FAQ2
In which component of Dolibarr does CVE-2026-19930 exist?
This vulnerability exists in the 'User Cloning' component within the 'card.php' file of the Dolibarr platform.
What is the primary mitigation recommended for CVE-2026-19930?
Users are advised to immediately update to the latest patched version of Dolibarr and enforce strict input sanitization.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.