A vulnerability affecting Dolibarr ERP/CRM, identified as CVE-2026-89013, has been added to VulnCheck's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. The flaw was publicly disclosed on September 11, 2026, and exploitation was first reported just six days later, on September 17, 2026.
The vulnerability's inclusion in the VulnCheck KEV catalog, which was mirrored by the CIRCL aggregator, is the primary confirmation of its active exploitation. As of the latest information, neither the U.S. CISA KEV nor the EUVD (ENISA) KEV catalogs have listed CVE-2026-89013.
While the specific nature of the vulnerability (e.g., path traversal, remote code execution) has not been detailed in the available information, its rapid exploitation following disclosure highlights the urgency for users of Dolibarr ERP/CRM to apply any available patches or mitigation measures. The CVSS severity score for this vulnerability is currently listed as "none," which may indicate that a full assessment is pending or that the impact varies depending on the specific configuration.
The Exploit Prediction Scoring System (EPSS) for CVE-2026-89013 is 1.6%, placing it in the 74.3rd percentile. This metric suggests a relatively low probability of exploitation compared to all other vulnerabilities, yet the confirmed active exploitation underscores that even vulnerabilities with lower EPSS scores can be targeted.
The timeline of the vulnerability shows that the CVE was reserved on September 10, 2026, published on September 11, 2026, and first listed as exploited on September 17, 2026. This six-day window between public disclosure and confirmed exploitation is a critical period for defenders to address such threats.
Dolibarr ERP/CRM is an open-source enterprise resource planning and customer relationship management software used by various organizations. The confirmed exploitation of a vulnerability in such a widely used system poses a significant risk to its user base.
Users are advised to monitor official Dolibarr channels for security advisories and patch releases related to CVE-2026-89013. Given the confirmed exploitation, prompt action is recommended to secure affected installations.






