CVE-2026-25137Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the database manager without any authentication. This allows unauthorized actors to delete and download the entire database, including Odoos file store. Unauthorized access is evident from http requests. If kept, searching access logs and/or Odoos log for requests to /web/database can give indicators, if this has been actively exploited. The database manager is a featured intended for development and not meant to be publicly reachable. On other setups, a master password acts as 2nd line of defence. However, due to the nature of NixOS, Odoo is not able to modify its own configuration file and thus unable to persist the auto-generated password. This also applies when manually setting a master password in the web-UI. This means, the password is lost when restarting Odoo. When no password is set, the user is prompted to set one directly via the database manager. This requires no authentication or action by any authorized user or the system administrator. Thus, the database is effectively world readable by anyone able to reach Odoo. This vulnerability is fixed in 25.11 and 26.05.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-552

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-02-02); latest day: 1
  • 9 total mentions across 5 days

Deep dive

Activity timeline9 mentions / 5d
01223Mentions · 2026-02-02: 3Mentions · 2026-02-03: 3Mentions · 2026-02-04: 1Mentions · 2026-02-06: 1Mentions · 2026-02-23: 1Patch / Workaround · 2026-02-03: 2Patch / Workaround · 2026-02-23: 1Technical Details · 2026-02-02: 3Technical Details · 2026-02-03: 3Technical Details · 2026-02-04: 1Technical Details · 2026-02-06: 1Technical Details · 2026-02-23: 102-0202-0302-0402-0602-23
Signal classification3 categories
Disclosure
555.6%
Patch
333.3%
General
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-02-023
Disclosure3
2026-02-033
General1Patch2
2026-02-041
Disclosure1
2026-02-061
Disclosure1
2026-02-231
Patch1
Full discourse9 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Critical exposure in #Odoo on #NixOS (#CVE-2026-25137, CVSS:9.1). By default, every NixOS based Odoo setup publicly exposes the database manager without any authentication, letting anyone with access dump or delete the database. https://ccb.belgium.be/advisories/warning-critical-unauthenticated-database-manager-exposure-odoo-nixos-patch-immediately  #Patch #Patch

    Post summary

    A critical Odoo database manager exposure on NixOS (CVE-2026-25137, CVSS 9.1) has been identified, and a patch is immediately available.

    02011312
    7.2K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25137 - Critical The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the database manager without any authentic... https://www.thehackerwire.com/vulnerability/CVE-2026-25137/ https://t.co/fg300n8QGD

    Post summary

    CVE-2026-25137 discloses that NixOS Odoo installations from 21.11 to before 25.11 and 26.05 publicly expose the database manager without authentication; no PoC, exploit, or patch details are provided.

    1001198
    113 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 Critical Odoo Vulnerability #CVE-2026-25137 Exposes ERP Databases on NixOS – Patch Now! https://undercodetesting.com/critical-odoo-vulnerability-cve-2026-25137-exposes-erp-databases-on-nixos-patch-now/ Educational Purposes!

    Post summary

    The post alerts readers to a critical Odoo CVE that exposes ERP databases on NixOS and urges immediate patching.

    0000065
    399 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    OdooをNixOSで動かす企業は要注意、脆弱性 CVE-2026-25137でDBマネージャが未認証公開になるリスク https://rocket-boys.co.jp/security-measures-lab/odoo-on-nixos-users-warned-cve-2026-25137-risks-exposing-db-manager-without-authentication/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The article highlights a newly disclosed CVE‑2026‑25137 that risks exposing the Odoo database manager on NixOS without authentication.

    00000163
    318 followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    CVE-2026-25137: Critical Odoo on NixOS Flaw Exposes Databases https://securityonline.info/cve-2026-25137-critical-odoo-on-nixos-flaw-exposes-databases/

    Post summary

    CVE-2026-25137 is a newly disclosed critical vulnerability in Odoo on NixOS that can expose databases; the text provides only basic disclosure information without PoC, exploit, or patch details.

    0000043
    73 followersView on X
  • PulsePatch.io@pulsepatchio
    General

    NixOS Nixpkgs Odoo deployments are susceptible to CVE-2026-25137, which can expose database and filestore data by default. Address configurations. #NixOS #Odoo #infosec https://www.pulsepatch.io/posts/cve-2026-25137-nixos-nixpkgs-odoo-data-exposure

    Post summary

    The post notes that NixOS Nixpkgs Odoo deployments are vulnerable to CVE-2026-25137, potentially exposing database and filestore data, but offers no PoC, exploit, or patch details.

    0000054
    1 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25137: CRITICAL] NixOS based Odoo setups exposed database manager without authentication, allowing unauthorized access to delete/download databases. Vulnerability fixed in versions 25.11 and 26.05.#cve,CVE-2026-25137,#cybersecurity https://cvefind.com/CVE-2026-25137

    Post summary

    A critical CVE affecting NixOS‑based Odoo installations has been disclosed, exposing an unauthenticated database manager that permits deletion/download of databases; the issue is fixed in specific Odoo releases.

    0000085
    583 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25137 The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the database manager … https://www.cve.org/CVERecord?id=CVE-2026-25137

    Post summary

    CVE-2026-25137 reveals that NixOS Odoo setups expose the database manager publicly; the post contains no PoC, exploit code, or patch details.

    00000152
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25137: NixOs Odoo database and filestor... NixOS Odoo's ephemeral master password design creates a perfect storm: unauthenticated database manager exposure lettin... https://zerodaysignal.com/vulnerability/CVE-2026-25137 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-25137, highlighting an unauthenticated database manager exposure in NixOS Odoo’s master password design, but provides no PoC, exploit, patch, or active exploitation information.

    0000045
    132 followersView on X

Explore more