logo

CVE-2026-25137: Critical Odoo on NixOS Flaw Exposes Databases

ID: c3c8642f-afea-543b-8a14-4c6115191026

STIX ID: report--c3c8642f-afea-543b-8a14-4c6115191026

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical CVE-2026-25137 vulnerability (CVSS 9.1) affects Odoo on NixOS: because NixOS immutability prevents Odoo from persisting its auto-generated master database password, the database manager may be left unsecured after restarts, allowing anyone who can reach /web/database to set the password and gain full administrative access (data exfiltration or deletion). Patches are available for affected NixOS releases and the recommended mitigation is to disable the database manager in NixOS configuration (services.odoo.settings.options.list_db = false) or block access to /web/database until patched; administrators should check access logs for signs of unauthorized access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.