CVE ID: CVE-2021-23176 Affected Versions: Odoo 15.0 and earlier (Community and Enterprise Editions) Component: l10n_fr_fec Issue: Improper access control in reporting engine allows remote authenticated users to extract accounting information via crafted RPC packets. Impact: - Attack Vector: Network exploitable - Authentication: Employee / Portal user account required - CVSS3 Score: Medium (6.5) Workaround: Temporarily uninstall the l10n_fr_fec module on unpatched databases. Solution: Update to the latest revision via GitHub or download from the provided link. Alternatively, apply the corresponding patch. Patches: - 13.0: 0ef5489 - 14.0: f166400 - 15.0: 66f0a38 Enterprise Versions: See corresponding patches for 15.0, 14.0, and 13.0.