CVE-2026-27626Disclosure(olivetin / olivetin)

HIGHCVSS 9.9 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch olivetin olivetin systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety check (`checkShellArgumentSafety`) blocks several dangerous argument types but not `password`. A user supplying a `password`-typed argument can inject shell metacharacters that execute arbitrary OS commands. A second independent vector allows unauthenticated RCE via webhook-extracted JSON values that skip type safety checks entirely before reaching `sh -c`. When exploiting vector 1, any authenticated user (registration enabled by default, `authType: none` by default) can execute arbitrary OS commands on the OliveTin host with the permissions of the OliveTin process. When exploiting vector 2, an unauthenticated attacker can achieve the same if the instance receives webhooks from external sources, which is a primary OliveTin use case. When an attacker exploits both vectors, this results in unauthenticated RCE on any OliveTin instance using Shell mode with webhook-triggered actions. As of time of publication, a patched version is not available.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • olivetin

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 7 classified signals
  • Peaked 3d ago at 5 mentions (2026-02-25); latest day: 3
  • 10 total mentions across 4 days

Affected systems

Vendors
Products
olivetin

Deep dive

Activity timeline10 mentions / 4d
01345Mentions · 2026-02-25: 5Mentions · 2026-02-26: 1Mentions · 2026-03-02: 1Mentions · 2026-09-25: 3PoC Mentioned / Linked · 2026-09-25: 2Exploit Tool / Code · 2026-09-25: 1Active Exploitation · 2026-09-25: 1Patch / Workaround · 2026-02-25: 2Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-25: 5Technical Details · 2026-02-26: 1Technical Details · 2026-03-02: 102-2502-2603-0209-25
Signal classification4 categories
Disclosure
770.0%
Patch
110.0%
Active Exploitation
110.0%
Exploit
110.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-255
Disclosure4Patch1
2026-02-261
Disclosure1
2026-03-021
Disclosure1
2026-09-253
Active Exploitation1Disclosure1Exploit1
Full discourse10 posts
  • ExploitGrid@exploitgrid
    Active Exploitation

    💀 CRITICAL Exploits Trending ├ CVE-2026-27626 · CVE-2026-86218 · PoC live ├ CVE-2020-14645 — WebLogic · PoC live (still getting hit 6 yrs later) └ CVE-2026-5118 · CVE-2026-62878 · PoC live

    Post summary

    The text highlights several critical exploits with live PoCs, noting that CVE-2020-14645 for WebLogic is still being actively exploited after six years.

    1000056
    330 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] CVE-2026-27626 [CRITICAL/PoC] Enigm-Writeup 🔗 https://exploitgrid.net/exploits/70713923-d687-4b8b-9297-d597aa3337f7

    Post summary

    The text announces CVE-2026-27626 as critical with an available exploit and PoC linked to an external repository, but provides no patch, technical details, or evidence of active exploitation.

    1000060
    330 followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2026-27626 CVE-2026-86218 CVE-2020-14645 CVE-2026-5118 CVE-2026-62878 ..🧵👇

    Post summary

    The tweet lists several CVE identifiers as critical exploits disclosed today, without providing technical details, proof of concept, exploit code, patches, or evidence of active exploitation.

    1000060
    330 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical OS command injection in #OliveTin (CVE-2026-27626, CVSS 10). Two vectors can be chained to allow unauthenticated remote code execution on any OliveTin instance using Shell mode with webhook-triggered actions. Act now to secure your systems! #RCE #Patch #Patch

    Post summary

    A critical OS command injection (CVE‑2026‑27626) in OliveTin allows unauthenticated remote code execution; users are urged to apply patches immediately.

    01000231
    7.2K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27626 (CVSS:9.9, CRITICAL) is Analyzed. OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, Oliv..https://nvd.nist.gov/vuln/detail/CVE-2026-27626 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-27626, a critical vulnerability in OliveTin that permits execution of predefined shell commands through its web interface, but it does not provide any PoC, exploit, or patch information.

    0000035
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    CVE-2026-27626: `OliveTin` is vulnerable to OS Command Injection via `password` argument in webhook JSON processing. This bypasses shell safety. Review `OliveTin` configs. #InfoSec #Vulnerability https://www.pulsepatch.io/posts/cve-2026-27626-olivetin-os-command-injection

    Post summary

    The post announces a new OS Command Injection vulnerability in OliveTin, detailing the flaw and recommending configuration review as a mitigation.

    0000044
    1 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27626: OliveTin: When 'Safe' Shell Execution Goes Rogue (CVE-2026-27626) OliveTin, a tool designed to simplify shell command execution for end-users, suffers from two critical Command Injection vulnerabilities (CVE-2026-27626). By failing to ... https://cvereports.com/reports/CVE-2026-27626

    Post summary

    OliveTin is affected by two critical command injection vulnerabilities (CVE-2026-27626), as reported by cvereports.com.

    0000038
    31 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27626 OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety check (`checkShellArg… https://www.cve.org/CVERecord?id=CVE-2026-27626

    Post summary

    OliveTin’s shell mode safety check flaw allows a web interface to execute predefined shell commands, affecting versions up to 3000.10.0.

    00000110
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-27626: CRITICAL] Warning: OliveTin software up to v3000.10.0 is vulnerable to RCE attacks via shell arguments and webhook-extracted JSON values. Patch not yet available. #cybersecurity#cve,CVE-2026-27626,#cybersecurity https://cvefind.com/CVE-2026-27626

    Post summary

    OliveTin versions up to v3000.10.0 are vulnerable to remote code execution via shell arguments and webhook‑extracted JSON values, and no patch is currently available.

    0000058
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-27626 pertains to a critical security flaw in OliveTin, a platform that provides a web interface for executing shell commands. The vulnerability arises from inadequate input validation and safety checks within the application's shell command execution mechanism, particularly in its "shell mode." #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2026-27626

    Post summary

    CVE-2026-27626 is a critical flaw in OliveTin caused by inadequate input validation in its shell mode, potentially allowing remote code execution.

    0000043
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appolivetinolivetin---

Explore more