CVE-2026-28789Disclosure(olivetin / olivetin)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerability exists in OliveTin’s OAuth2 login flow. Concurrent requests to /oauth/login can trigger unsynchronized access to a shared registeredStates map, causing a Go runtime panic (fatal error: concurrent map writes) and process termination. This allows remote attackers to crash the service when OAuth2 is enabled. This issue has been patched in version 3000.10.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362CWE-400CWE-662

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • olivetin

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
olivetin

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-05: 2Mentions · 2026-03-06: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 103-0503-06
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-052
Disclosure1General1
2026-03-061
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28789 Unauthenticated Denial-of-Service Vulnerability in OliveTin OAuth... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28789 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post shares CVE‑2026‑28789, describing it as an unauthenticated denial‑of‑service vulnerability in OliveTin OAuth and linking to a Vulmon details page for further information.

    0000061
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28789 Intel Report: https://ift.tt/RkH4t9m

    Post summary

    The alert cites CVE-2026-28789 and links to an Intel report, but gives no further technical or exploit details.

    0000037
    343 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28789 OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerability exists in Oliv… https://www.cve.org/CVERecord?id=CVE-2026-28789

    Post summary

    CVE-2026-28789 exposes an unauthenticated denial‑of‑service flaw in OliveTin’s web interface before version 3000.10.3; no PoC, exploit, or patch details are provided.

    0000085
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appolivetinolivetin---

Explore more