A vulnerability was found in Dolibarr ERP CRM up to 23.0.2. It has been rated as critical. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy Filemanager. The manipulation leads to improper authorization.

This vulnerability is traded as CVE-2026-11619. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

Upgrading the affected component is advised.