CVE-2026-25137: Critical Odoo on NixOS Flaw Exposes Databases
ID: c3c8642f-afea-543b-8a14-4c6115191026
STIX ID: report--c3c8642f-afea-543b-8a14-4c6115191026
Feed Name: securityonline.info
A critical CVE-2026-25137 vulnerability (CVSS 9.1) affects Odoo on NixOS: because NixOS immutability prevents Odoo from persisting its auto-generated master database password, the database manager may be left unsecured after restarts, allowing anyone who can reach /web/database to set the password and gain full administrative access (data exfiltration or deletion). Patches are available for affected NixOS releases and the recommended mitigation is to disable the database manager in NixOS configuration (services.odoo.settings.options.list_db = false) or block access to /web/database until patched; administrators should check access logs for signs of unauthorized access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
