CVE-2026-30225Disclosure(olivetin / olivetin)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication context confusion vulnerability in RestartAction allows a low‑privileged authenticated user to execute actions they are not permitted to run. RestartAction constructs a new internal connect.Request without preserving the original caller’s authentication headers or cookies. When this synthetic request is passed to StartAction, the authentication resolver falls back to the guest user. If the guest account has broader permissions than the authenticated caller, this results in privilege escalation and unauthorized command execution. This vulnerability allows a low‑privileged authenticated user to bypass ACL restrictions and execute arbitrary configured shell actions. This issue has been patched in version 3000.11.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250CWE-441

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • olivetin

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
olivetin

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-07: 2Technical Details · 2026-03-07: 203-07
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-30225 OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication context confusion vulnerability in RestartActio… https://www.cve.org/CVERecord?id=CVE-2026-30225

    Post summary

    The post describes CVE-2026-30225, an authentication context confusion flaw in OliveTin that enables execution of predefined shell commands via its web interface in versions before 3000.11.1, without mention of PoC, exploit code, active use, or remediation.

    0000099
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30225 Authentication Bypass in OliveTin RestartAction Leading to Privilege Escalation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30225

    Post summary

    The text announces an authentication bypass in OliveTin's RestartAction that enables privilege escalation, providing technical details but no PoC, exploit code, patch, or evidence of active exploitation.

    0000055
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appolivetinolivetin---

Explore more