CVE-2024-36259: Odoo

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.

Affected products

  • Odoo Odoo: version 17.0 only

Published 2025-02-25. Last modified 2026-06-17.