Skip to main content
CRITICAL

CVE-2026-25137

CVSS v3

9.1

CRITICAL

EPSS Score

9.9 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the database manager without any authentication. This allows unauthorized actors to delete and download the entire database, including Odoos file store. Unauthorized access is evident from http requests. If kept, searching access logs and/or Odoos log for requests to /web/database can give indicators, if this has been actively exploited. The database ma

Technical details

Published
2026-02-02
Last Modified
2026-04-14

Frequently asked questions

What is CVE-2026-25137?

The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the database manager without any authentication. This allows unauthorized actors to delete and download the entire database, including Odoos file store. Unauthorized access is evident from http requests. If kept, searching access logs and/or Odoos log for requests to /web/database can give indicators, if this has been actively exploited. The database ma

Is CVE-2026-25137 actively exploited?

Active exploitation of CVE-2026-25137 has not been confirmed. Its EPSS score was 9.9% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-25137?

CVE-2026-25137 has a CVSS v3 base score of 9.1 (CRITICAL severity).

Is CVE-2026-25137 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key