logo

Warning: Critical Unauthenticated Database Manager Exposure in Odoo on NixOS, Patch Immediately!

ID: 00dd3df8-1974-57e1-af95-273e03be4116

STIX ID: report--00dd3df8-1974-57e1-af95-273e03be4116

Feed Name: CCB Advisories Feed

Threat Score
80/100

Date Published: 2026-02-05

Date Updated: 2026-07-24

...
...

**Critical unauthenticated access in NixOS Odoo database manager (CVE-2026-25137):** A vulnerability in the NixOS-packaged Odoo Database Manager allows unauthenticated remote access to the /web/database endpoint, enabling attackers to enumerate, dump, or delete ERP databases and associated filestores across multiple Odoo versions (CVSS 9.1); no active exploitation has been reported but the potential confidentiality and availability impact is high.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.