Skip to Content
Odoo Menu
  • Sign in
  • Try it free
  • Apps
    Finance
    • Accounting
    • Invoicing
    • Expenses
    • Spreadsheet (BI)
    • Documents
    • Sign
    Sales
    • CRM
    • Sales
    • POS Shop
    • POS Restaurant
    • Subscriptions
    • Rental
    Websites
    • Website Builder
    • eCommerce
    • Blog
    • Forum
    • Live Chat
    • eLearning
    Supply Chain
    • Inventory
    • Manufacturing
    • PLM
    • Purchase
    • Maintenance
    • Quality
    Human Resources
    • Employees
    • Recruitment
    • Time Off
    • Appraisals
    • Referrals
    • Fleet
    Marketing
    • Social Marketing
    • Email Marketing
    • SMS Marketing
    • Events
    • Marketing Automation
    • Surveys
    Services
    • Project
    • Timesheets
    • Field Service
    • Helpdesk
    • Planning
    • Appointments
    Productivity
    • Discuss
    • Artificial Intelligence
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Industries
    Retail
    • Book Store
    • Clothing Store
    • Furniture Store
    • Grocery Store
    • Hardware Store
    • Toy Store
    Food & Hospitality
    • Bar and Pub
    • Restaurant
    • Fast Food
    • Guest House
    • Beverage Distributor
    • Hotel
    Real Estate
    • Real Estate Agency
    • Architecture Firm
    • Construction
    • Property Management
    • Gardening
    • Property Owner Association
    Consulting
    • Accounting Firm
    • Odoo Partner
    • Marketing Agency
    • Law firm
    • Talent Acquisition
    • Audit & Certification
    Manufacturing
    • Textile
    • Metal
    • Furnitures
    • Food
    • Brewery
    • Corporate Gifts
    Health & Fitness
    • Sports Club
    • Eyewear Store
    • Fitness Center
    • Wellness Practitioners
    • Pharmacy
    • Hair Salon
    Trades
    • Handyman
    • IT Hardware & Support
    • Solar Energy Systems
    • Shoe Maker
    • Cleaning Services
    • HVAC Services
    Others
    • Nonprofit Organization
    • Environmental Agency
    • Billboard Rental
    • Photography
    • Bike Leasing
    • Software Reseller
    Browse all Industries
  • Community
    Learn
    • Tutorials
    • Documentation
    • Certifications
    • Training
    • Blog
    • Podcast
    Empower Education
    • Education Program
    • Scale Up! Business Game
    • Visit Odoo
    Get the Software
    • Download
    • Compare Editions
    • Releases
    Collaborate
    • Github
    • Forum
    • Events
    • Translations
    • Become a Partner
    • Services for Partners
    • Register your Accounting Firm
    • Referral Program
    Get Services
    • Find a Partner
    • Find an Accountant
    • Meet an advisor
    • Implementation Services
    • Customer References
    • Support
    • Upgrades
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Get a demo
  • Pricing
  • Help
You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
odoo accounting v14 pos v15
About this forum
You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
odoo accounting v14 pos v15
About this forum
Help

Need to ensure that our Odoo environment is clean and secure

Subscribe

Get notified when there's activity on this post

This question has been flagged
security
1 Reply
57 Views
Avatar
Razan Saleh

Hello,

We recently engaged a third-party company to do some needed customizations on our account. Unfortunately, the engagement did not proceed as expected. 

As a precaution, we have already revoked their access to our Odoo environment and all related systems, changed all passwords, and reviewed user permissions. However, we remain concerned about the possibility that they may have implemented unauthorized modifications, hidden administrative accounts, backdoors, custom code, scheduled jobs, API integrations, or other mechanisms that could allow future access or negatively impact our operations.

We would appreciate your guidance on the following:

1. What risks should we realistically be concerned about in this situation?

2. What steps can we take to verify that our Odoo environment is secure and free from any unauthorized access mechanisms?

3. Are there specific audits, logs, security reviews, or code inspections that you would recommend?

4. Would creating a completely new Odoo instance and migrating all data and customizations to it eliminate these risks, or could vulnerabilities be transferred as part of the migration?

5. Are there any additional best practices we should follow to ensure the integrity and security of our system going forward?


0
Avatar
Discard
Codesphere Tech

Hello
This is a serious situation, and your proactive steps—revoking access, rotating credentials, and reviewing permissions—were exactly the right first moves to contain the immediate risk.
Realistic Risks to Consider:
-> Hidden lines of code (in custom modules) that create new administrator users or allow remote command execution.
-> Malicious automated tasks that periodically exfiltrate data, delete logs, or create new unauthorized users.(schedule actions)
-> New endpoints created to transmit data to an external server.
-> Users created with low-privilege names that have hidden "Superuser" or "Administrator" access rights.
-> Code designed to subtly alter accounting entries, inventory counts, or pricing at a future date.
Let me know if you need any help on this
I'm happy to help you in this situation.
Thanks

Avatar
Zehntech Technologies Inc.
Best Answer

Hello,

Your concerns are valid, especially after third-party customizations. In Odoo, the main areas to review would typically include:

• User accounts and access groups (including inactive/admin users)

• Custom modules and code changes introduced during the engagement

• Scheduled actions (cron jobs), server actions, and automated scripts

• API keys, webhooks, external integrations, and connected services

• Audit logs and recent activity history

• Database-level changes and custom security rules

Creating a new Odoo instance can reduce risk, but simply migrating existing customizations without reviewing them may transfer the same vulnerabilities. Data migration itself is generally safer than blindly moving custom code and integrations.

As a best practice, perform a full security and customization audit, validate all deployed modules, enforce least-privilege access, enable stronger authentication practices, and maintain proper documentation/change control going forward.

Hope this works for you! If you need any help implementing this or want a more optimized approach, feel free to reach out for further discussion.

Regards,

Zehntech Technologies Inc.

santosh.sekwadia@zehntech.com

0
Avatar
Discard
Enjoying the discussion? Don't just read, join in!

Create an account today to enjoy exclusive features and engage with our awesome community!

Sign up
Related Posts Replies Views Activity
Local Odoo 19 Database: Inventory not showing on Hand?
security
Avatar
0
Apr 26
5
User: Access Rules Not Updating After Sales Unit Change
security
Avatar
0
Mar 26
3
cubic milimeters to cubic meters conversion
security
Avatar
0
Mar 26
4
Mac Id restriction for Users in Odoo enterprise Solved
security
Avatar
Avatar
1
Dec 25
1577
what is the differance between access right and record rules in odoo ? Solved
security
Avatar
Avatar
Avatar
Avatar
Avatar
5
Sep 25
18300
Community
  • Tutorials
  • Documentation
  • Forum
Open Source
  • Download
  • Github
  • Runbot
  • Translations
Services
  • Odoo.sh Hosting
  • Support
  • Upgrade
  • Custom Developments
  • Education
  • Find an Accountant
  • Find a Partner
  • Become a Partner
About us
  • Our company
  • Brand Assets
  • Contact us
  • Jobs
  • Events
  • Podcast
  • Blog
  • Customers
  • Legal • Privacy
  • Security
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk Slovenščina Español (América Latina) Español Svenska ภาษาไทย Türkçe українська Tiếng Việt

Odoo is a suite of open source business apps that cover all your company needs: CRM, eCommerce, accounting, inventory, point of sale, project management, etc.

Odoo's unique value proposition is to be at the same time very easy to use and fully integrated.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now