← Vulnerability feed

Vulnerability record · CVE-2017-9416 · published 4 June 2017

CVE-2017-9416: Odoo path traversal vulnerability

Odoo · Odoo

Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.

6.5 CVSS 3.0 Medium EPSS 5.7% · top 7.3% CWE-22 · Path traversal
6.5CVSS 3.0 base score, v2 4.0
5.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/odoo/odoo/issues/17394 Issue TrackingPatchThird Party Advisory
https://github.com/odoo/odoo/issues/17394 Issue TrackingPatchThird Party Advisory

Track CVE-2017-9416 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-14885Odoo improper access control vulnerabilityIncorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker…EPSS 2.2%9.8CVE-2017-10804Odoo missing authentication for critical function vulnerabilityIn Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain …EPSS 3.4%9.1CVE-2021-44547Odoo vulnerabilityA sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privile…EPSS 0.70%9.1CVE-2018-15632Odoo improper input validation vulnerabilityImproper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers…EPSS 1.2%9.1CVE-2018-14860Odoo os command injection vulnerabilityImproper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privil…EPSS 2.2%8.8CVE-2024-12368Odoo improper access control vulnerabilityImproper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens o…EPSS 0.69%8.8CVE-2019-11781Odoo improper input validation vulnerabilityImproper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to tri…EPSS 2.1%8.8CVE-2020-29396Odoo vulnerabilityA sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote au…EPSS 3.2%

Source: NIST National Vulnerability Database (record CVE-2017-9416), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.