Wednesday, September 2, 2026
3 changes · 19.0
Security fixes and vulnerability patches
Public job applications can no longer overwrite an existing employee or internal user's contact name just by using their email address. This protects contact records from unauthorized changes while still allowing applications to match contacts by email when appropriate.
Original PR description
Issue: An unauthenticated visitor can submit a public job application with an internal user's email address and another applicant name. The submission then replaces the internal user's display name.…
Issue: An unauthenticated visitor can submit a public job application with an internal user's email address and another applicant name. The submission then replaces the internal user's display name. Steps to reproduce: - Create an internal user and publish a job position. - Apply anonymously using the internal user's email and a different name. - Observe that the internal user's display name is replaced. Cause: `_inverse_partner_email()` handles a partner found from the submitted email as if it had already been explicitly linked to the applicant. It then synchronizes the untrusted applicant values onto that partner. Since public applications are created with elevated privileges, the email only match can modify an internal user's contact. https://github.com/odoo/odoo/blob/3b343f7b865bb1f57802f6df881ce4531d02c1ad/addons/hr_recruitment/models/hr_applicant.py#L228-L247 Solution: Use the applicant details only when the email lookup creates a new partner, and stop synchronization after an implicit email match. This allows applications to remain linked by email without letting the match modify an existing contact, while preserving synchronization for partners already explicitly linked to an applicant. opw-6472303 --- I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr Forward-Port-Of: odoo/odoo#285389 Forward-Port-Of: odoo/odoo#283546
Resolved issues and error corrections
This fix ensures that data loss prevention activity is recorded when a spreadsheet is frozen. It improves auditability and helps businesses track sensitive document actions more reliably.
Original PR description
Task: 6389096 Forward-Port-Of: odoo/enterprise#128749 Forward-Port-Of: odoo/enterprise#126461
Customer-facing invoice pages no longer show the salesperson's city or phone number. This makes invoice information consistent with sales orders and helps avoid exposing personal employee details to customers.
Original PR description
This change aligns the salesperson's information shown to customers on the invoice view with those shown on the sales order view. Now city and phone number are not shown and both views are consistent. This information can be personal information not supposed to be leaked to customers especially the salesperson's city in case of home office. --- I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr Forward-Port-Of: odoo/odoo#278497