Sceawere

Vulnerability Detail

CVE-2026-108861UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Odoo MCP Field-Level ACL Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
erpipe-org
Product
Odoo MCP
Attack Type
Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Odoo MCP 1.0.0 through 1.3.2 contains an information disclosure vulnerability that allows MCP clients to bypass the field-level ACL by invoking the execute_method tool. Attackers or prompt-injected agents can call read or search_read through execute_method naming denied fields to receive their values unredacted.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T14:17:06.077Z",
  "pubdate": "2026-10-11T14:17:06.077Z",
  "executiveSummary": "Odoo MCP versions 1.0.0 through 1.3.2 are susceptible to an information disclosure vulnerability stemming from insufficient access control enforcement within the execute_method tool.\nThe vulnerability allows authenticated MCP clients or compromised agents to circumvent field-level access control lists (ACLs) by programmatically invoking sensitive methods.\nBy leveraging the execute_method tool, an attacker can execute read or search_read operations on restricted fields that should otherwise be redacted based on the user's defined permissions.\nThis vulnerability exposes sensitive business logic and data, potentially leading to unauthorized disclosure of proprietary information.\nSuccessful exploitation requires the ability to interact with the Odoo MCP interface, which could be initiated via direct access or indirect prompt injection in an AI-integrated environment.\nThe risk is significant as it undermines the integrity of the Odoo security model regarding data visibility.",
  "technicalDetails": "The core issue resides in the insufficient validation of user-requested method execution within the Odoo MCP interface. The execute_method tool acts as a bridge, allowing clients to invoke arbitrary methods on models without adequate security context validation for the specific field-level permissions.\nWhen a request is processed via execute_method, the system fails to verify whether the invoking client has the necessary ACL rights to access specific fields requested during read or search_read operations. This decoupling of the execution capability from the field-level authorization logic allows the bypass.\nThe exploitation flow begins when an attacker or a prompt-injected agent constructs a payload targeting the execute_method function. The attacker specifies a model and a method, such as read or search_read, passing a list of sensitive fields in the argument payload.\nBecause the server-side logic in Odoo MCP 1.0.0 to 1.3.2 does not perform a secondary check against the Odoo ORM (Object-Relational Mapping) field security constraints after invoking the method, the data is retrieved and returned in an unredacted state to the caller.\nThis vulnerability effectively elevates the privileges of the MCP client, granting read access to attributes that are explicitly denied in the Odoo security backend.\nThe impact is a full disclosure of any data reachable via the read or search_read methods on any model the client has general access to, regardless of field-level restrictions defined in the system's security rules.\nThere is no requirement for administrative privileges; standard user credentials assigned to an MCP client suffice to initiate the request, provided the client has permission to utilize the execute_method tool itself. The exposure is persistent across any deployment using the affected MCP versions where field-level security is a critical control."
}
CVE-2026-108861: Odoo MCP Field-Level ACL Bypass (MEDIUM Severity, CVSS: 4.3) | Sceawere