MEDIUM
erpipe-org
CVE published 2026-10-11
CVE-2026-108861
CVE-2026-108861 Odoo MCP Information Disclosure via execute_method Tool. This vulnerability allows MCP clients to bypass field-level ACL, potentially leading to information disclosure in Odoo MCP deployments. Defenders should assess exposure and prioritize verification and mitigation. The vulnerability exists in Odoo MCP versions 1.0.0 through 1.3.2 and involves invoking the execute_method tool to access [truncated]