THREATPORT/VULNERABILITY/CVE-2026-25137
CRITICAL SEVERITY

CVE-2026-25137

CVE-2026-25137 vulnerability

CVSS
9.1
EPSS
9.5%
EPSS pct
95th
Exploited
No known
The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the database manager without any authentication. This allows unauthorized actors to delete and download the entire database, including Odoos file store. Unauthorized access is evident from http requests. If kept, searching access logs and/or Odoos log for requests to /web/database can give indicators, if this has been actively exploited. The database manager is a featured intended for development and not meant to be publicly reachable. On other setups, a master password acts as 2nd line of defence. However, due to the nature of NixOS, Odoo is not able to modify its own configuration file and thus unable to persist the auto-generated password. This also applies when manually setting a master password in the web-UI. This means, the password is lost when restarting Odoo. When no password is set, the user is prompted to set one directly via the database manager. This requires no authentication or action by any authorized user or the system administrator. Thus, the database is effectively world readable by anyone able to reach Odoo. This vulnerability is fixed in 25.11 and 26.05.
Affected vendor
See references
Affected product
See references
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Weakness type (CWE)
  • CWE-306 — Missing Authentication for Critical Function
  • CWE-552 — Files or Directories Accessible to External Parties
Published
2026-02-02

Risk analysis

Based on its CVSS vector, this vulnerability is exploitable over the network, low attack complexity, requiring no privileges, no user interaction. Successful exploitation leads to high impact to confidentiality, high impact to availability.

Its EPSS score of 9.5% reflects a lower probability of exploitation activity in the wild over the next 30 days, placing it above 95% of all scored CVEs.

Check your external exposure to CVE-2026-25137

  • Confirm whether the affected software is running on any internet-facing host or subdomain.
  • Match discovered service fingerprints against the version affected by CVE-2026-25137.
  • Prioritise remediation if the asset is public, business-critical, or near authentication/payment flows.

How ThreatPort helps with CVE-2026-25137

ThreatPort's external attack surface scanner checks your internet-facing assets — agentlessly, from the outside in — for the exposed services and versions that CVE-2026-25137 affects, then prioritises the finding by real risk using CISA KEV and FIRST.org EPSS.

Run a free external exposure scan

Are you exposed to CVE-2026-25137?

Run an instant, non-intrusive external scan to check your attack surface for CVE-2026-25137.

Start free scan

No credit card. Agentless.