Friday, August 28, 2026
2 changes · saas-18.4
Security fixes and vulnerability patches
When a database is neutralized for copying or sharing, saved outgoing email usernames and passwords are now cleared from archived mail server settings. This prevents real email relay credentials from being carried into test or shared database copies where they are not needed.
Original PR description
backport of odoo/odoo#284960 Forward-Port-Of: odoo/odoo#285221
Portal access tokens are now checked using exact matches only. This prevents similar or partial token values from being accepted, helping keep portal access limited to the intended links.
Original PR description
Access tokens can only be matched by exact value. Task-6481193 Forward-Port-Of: odoo/odoo#283130