Warning: Critical Unauthenticated Database Manager Exposure in Odoo on NixOS, Patch Immediately!
ID: 00dd3df8-1974-57e1-af95-273e03be4116
STIX ID: report--00dd3df8-1974-57e1-af95-273e03be4116
Feed Name: CCB Advisories Feed
Threat Score
**Critical unauthenticated access in NixOS Odoo database manager (CVE-2026-25137):** A vulnerability in the NixOS-packaged Odoo Database Manager allows unauthenticated remote access to the /web/database endpoint, enabling attackers to enumerate, dump, or delete ERP databases and associated filestores across multiple Odoo versions (CVSS 9.1); no active exploitation has been reported but the potential confidentiality and availability impact is high.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
