Medium severity4.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108861
CVE-2026-108861
Description
Odoo MCP 1.0.0 through 1.3.2 contains an information disclosure vulnerability that allows MCP clients to bypass the field-level ACL by invoking the execute_method tool. Attackers or prompt-injected agents can call read or search_read through execute_method naming denied fields to receive their values unredacted.
Affected products
2- Range: 1.0.0 - 1.3.2
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.