← Vulnerability feed

Vulnerability record · CVE-2017-10804 · published 4 July 2017

CVE-2017-10804: Odoo missing authentication for critical function vulnerability

Odoo · Odoo

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.

9.8 CVSS 3.0 Critical EPSS 3.4% · top 11.6% CWE-306 · Missing authentication for critical function
9.8CVSS 3.0 base score, v2 7.5
3.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-10804 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-14885Odoo improper access control vulnerabilityIncorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker…EPSS 2.2%9.1CVE-2021-44547Odoo vulnerabilityA sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privile…EPSS 0.70%9.1CVE-2018-15632Odoo improper input validation vulnerabilityImproper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers…EPSS 1.2%9.1CVE-2018-14860Odoo os command injection vulnerabilityImproper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privil…EPSS 2.2%8.8CVE-2024-12368Odoo improper access control vulnerabilityImproper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens o…EPSS 0.69%8.8CVE-2019-11781Odoo improper input validation vulnerabilityImproper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to tri…EPSS 2.1%8.8CVE-2020-29396Odoo vulnerabilityA sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote au…EPSS 3.2%8.8CVE-2018-15640Odoo improper access control vulnerabilityImproper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges …EPSS 7.8%

Source: NIST National Vulnerability Database (record CVE-2017-10804), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.