EIP-2026-104366

PRE-CVE

Odoo 12.0 - Local File Inclusion

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104366. PoCs published by Emre ÖVÜNÇ.

AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Odoo 12.0, allowing an attacker to read arbitrary files from the server via crafted HTTP requests to specific static file endpoints.

Description

Odoo 12.0 - Local File Inclusion

Exploits (1)

exploitdb WORKING POC
by Emre ÖVÜNÇ · textwebappsmultiple
https://www.exploit-db.com/exploits/48609

This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Odoo 12.0, allowing an attacker to read arbitrary files from the server via crafted HTTP requests to specific static file endpoints.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Odoo 12.0
No auth needed
Prerequisites: Network access to the Odoo instance · Odoo 12.0 running on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026