CVE-2026-25137 (CVSS 9.1) affects Odoo deployments packaged for NixOS, where the Odoo database manager can be exposed to the public internet without effective authentication under default configurations. The issue is not an Odoo upstream code flaw but a packaging/configuration interaction with NixOS’s immutable configuration model: Odoo cannot persist its auto-generated (or web-UI-set) master password to the configuration file, so after restarts the instance can return to a state where the next visitor to /web/database is prompted to set the master password, enabling a race-to-claim scenario.
If reachable externally, an unauthenticated attacker can use the database manager to download or delete the entire database and associated Odoo filestore, resulting in full data exfiltration and destructive impact. Detection guidance includes reviewing web/access logs and Odoo logs for HTTP requests to /web/database as potential indicators of exposure or exploitation. The vulnerability is reported to affect NixOS Odoo setups from 21.11 to before 25.11 and 26.05, and is fixed in NixOS 25.11 and 26.05.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
The issue was publicly disclosed as CVE-2026-25137 with a reported CVSS score of 9.1, drawing attention to the risk for Odoo deployments on NixOS. Public reporting highlighted the race condition and the potential for full database and filestore compromise.
The vulnerability was addressed in NixOS releases 25.11 and 26.05. Defenders were advised to apply the patches, disable the database manager or block access to /web/database, and review logs for requests to the exposed endpoint.
A vulnerability in the NixOS Odoo package caused the Odoo database manager endpoint to become exposed without authentication after restarts because the master password could not be persisted in NixOS configuration. This could let a remote attacker access, exfiltrate, or delete the database and Odoo filestore, and potentially set a new master password first.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.