CVE-2026-30223Disclosure(olivetin / olivetin)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch olivetin olivetin systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using either "authJwtPubKeyPath" (local RSA public key) or "authJwtHmacSecret" (HMAC secret), the configured audience value (authJwtAud) is not enforced during token parsing. As a result, validly signed JWT tokens with an incorrect aud claim are accepted for authentication. This allows authentication using tokens intended for a different audience/service. This issue has been patched in version 3000.11.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-345

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • olivetin

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-07)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
olivetin

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-06: 1Mentions · 2026-03-07: 3Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-07: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 203-0603-07
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-061
Patch1
2026-03-073
Disclosure3
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-30223 OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using either "authJwtPubKey… https://www.cve.org/CVERecord?id=CVE-2026-30223

    Post summary

    CVE‑2026‑30223 is a documented flaw in OliveTin that permits execution of predefined shell commands before version 3000.11.1, when certain JWT authentication settings are used.

    0000099
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-30223 - High OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using either "authJwtPubKeyPath" (local RSA public k... https://www.thehackerwire.com/vulnerability/CVE-2026-30223/ https://t.co/4ZGClI7AiO

    Post summary

    The tweet announces CVE‑2026‑30223, describes how OliveTin exposes shell commands via JWT credentials, and notes that the issue is fixed in OliveTin version 3000.11.1.

    0000048
    128 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30223 JWT Authentication Bypass in OliveTin Web Interface Prior to 3000.11.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30223

    Post summary

    Announcement of a JWT authentication bypass vulnerability (CVE-2026-30223) in OliveTin versions prior to 3000.11.1, with no additional technical, exploitation, or patch details provided.

    0000054
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30223: HIGH] OliveTin's security flaw allowed authentication using tokens meant for another service. Update to version 3000.11.1 to fix this vulnerability with JWT authentication.#cve,CVE-2026-30223,#cybersecurity https://cvefind.com/CVE-2026-30223

    Post summary

    OliveTin CVE-2026-30223 is an authentication bypass flaw that allows JWT tokens from another service to be used for authentication; users should upgrade to version 3000.11.1 to remediate the vulnerability.

    0000050
    597 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appolivetinolivetin---

Explore more