Open Source ERP System Exposes Database Manager Without Authentication
CVE-2026-25137
What is CVE-2026-25137?
The NixOS Odoo package, an open-source ERP and CRM system, suffers from a severe vulnerability that exposes the database manager without authentication. This configuration flaw enables unauthorized users to access, delete, and download the entire database along with its associated files. Users can identify potential exploitation by examining access logs for requests to the /web/database path. Unlike other setups where a master password provides an additional layer of security, the nature of NixOS prevents Odoo from modifying its configuration file, effectively rendering any manually set master password temporary and lost upon the Odoo restart. As a result, the database manager becomes publicly accessible, allowing any individual with network access to view sensitive data. This critical issue is addressed in the versions 25.11 and 26.05.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
nixpkgs >= 21.11, < 25.11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
