Information Disclosure in Odoo MCP by Odoo
CVE-2026-108861
5.3MEDIUM
What is CVE-2026-108861?
Odoo MCP versions 1.0.0 through 1.3.2 exhibit an information disclosure vulnerability that enables clients to bypass field-level access control lists (ACLs). By leveraging the execute_method tool, malicious actors can invoke read or search_read methods on restricted fields, allowing them to access sensitive data that should be protected from unapproved access. This vulnerability poses a significant risk as it could lead to unauthorized data retrieval, compromising user information and breach of confidentiality.
Affected Version(s)
Odoo MCP 1.0.0 <= 1.3.2
