CVE-2018-15640: Odoo

High severity, CVSS 8.8. EPSS: 7.8% chance of exploitation in the next 30 days.

Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request.

Affected products

  • Odoo Odoo: from 10.0, up to and including 12.0

Published 2019-04-09. Last modified 2026-06-17.