CVE-2017-10804: Odoo

Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.

Affected products

  • Odoo Odoo: version 8.0 only; version 9.0 only; version 10.0 only

Published 2017-07-04. Last modified 2026-06-17.