VYPR
Unrated severityNVD Advisory· Published Jul 3, 2019· Updated Aug 5, 2024

CVE-2018-14862

CVE-2018-14862

Description

Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated internal users to delete arbitrary menuitems via a crafted RPC request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated internal users can delete arbitrary menu items in Odoo 11.0 and earlier via a crafted RPC request abusing the mail templating system.

Vulnerability

In Odoo Community and Enterprise versions 9.0, 10.0, and 11.0 (and earlier), the mail templating system's shortcut removal mechanism lacks proper access control. An authenticated internal user can craft a malicious RPC request to delete arbitrary menuitems, not just their own shortcuts. The vulnerability resides in the mail component. [1]

Exploitation

An attacker needs a valid user account with network access to the Odoo instance. No special privileges are required beyond being an authenticated internal user. The attacker sends a crafted RPC request to the mail template endpoint, exploiting the shortcut removal functionality to target arbitrary menu entries. [1]

Impact

Successful exploitation allows the attacker to delete arbitrary menu items from the user interface. While no business data is lost, the system becomes difficult to use until repaired. The CVSS score is 7.1 (High) with vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H, indicating high availability impact. [1]

Mitigation

Odoo S.A. has released patches for all affected versions. Users should apply the corresponding patch or update to the latest revision. As a workaround, restrict create and write access to the mail.template model to trusted users only. Odoo Online servers were patched as soon as the correction was available. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.