Friday, August 28, 2026
3 changes · saas-18.3
Security fixes and vulnerability patches
When a database is neutralized for copying or testing, saved outgoing email server usernames and passwords are now cleared. This prevents real email relay credentials from being carried into shared database dumps where they are not needed.
Original PR description
backport of odoo/odoo#284960 Forward-Port-Of: odoo/odoo#285221
Portal access tokens are now only accepted when they exactly match the expected value. This prevents partial or overly broad matches while still supporting approved list-based checks, helping keep shared portal access reliable and secure.
Original PR description
Access tokens can only be matched by exact value. Accept `in` and `not in` operators. Task-6481193
This fix prevents anonymous job applications from changing the name of an existing contact when the applicant uses that contact's email address. Applications can still be associated by email, but unverified applicant details will no longer overwrite trusted internal contact records.
Original PR description
Issue: An unauthenticated visitor can submit a public job application with an internal user's email address and another applicant name. The submission then replaces the internal user's display name.…
Issue: An unauthenticated visitor can submit a public job application with an internal user's email address and another applicant name. The submission then replaces the internal user's display name. Steps to reproduce: - Create an internal user and publish a job position. - Apply anonymously using the internal user's email and a different name. - Observe that the internal user's display name is replaced. Cause: `_inverse_partner_email()` handles a partner found from the submitted email as if it had already been explicitly linked to the applicant. It then synchronizes the untrusted applicant values onto that partner. Since public applications are created with elevated privileges, the email only match can modify an internal user's contact. https://github.com/odoo/odoo/blob/3b343f7b865bb1f57802f6df881ce4531d02c1ad/addons/hr_recruitment/models/hr_applicant.py#L228-L247 Solution: Use the applicant details only when the email lookup creates a new partner, and stop synchronization after an implicit email match. This allows applications to remain linked by email without letting the match modify an existing contact, while preserving synchronization for partners already explicitly linked to an applicant. opw-6472303 --- I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr