CVE-2026-32102

OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution events and action output to authenticated dashboard subscribers without enforcing per-action authorization. A low-privileged authenticated user can receive output from actions they are not allowed to view, resulting in broken access control and sensitive information disclosure.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:olivetin:olivetin:*:*:*:*:*:*:*:*

History

17 Mar 2026, 15:34

Type Values Removed Values Added
CPE cpe:2.3:a:olivetin:olivetin:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
Summary
  • (es) OliveTin da acceso a comandos de shell predefinidos desde una interfaz web. En 3000.10.2 y anteriores, el EventStream en vivo de OliveTin transmite eventos de ejecución y la salida de acciones a suscriptores autenticados del panel de control sin aplicar autorización por acción. Un usuario autenticado con bajos privilegios puede recibir la salida de acciones que no tiene permitido ver, lo que resulta en un control de acceso roto y revelación de información sensible.
First Time Olivetin olivetin
Olivetin
References () https://github.com/OliveTin/OliveTin/security/advisories/GHSA-228v-wc5r-j8m7 - () https://github.com/OliveTin/OliveTin/security/advisories/GHSA-228v-wc5r-j8m7 - Exploit, Vendor Advisory

11 Mar 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 21:16

Updated : 2026-03-17 15:34


NVD link : CVE-2026-32102

Mitre link : CVE-2026-32102

CVE.ORG link : CVE-2026-32102


JSON object : View

Products Affected

olivetin

  • olivetin
CWE
CWE-284

Improper Access Control

CWE-863

Incorrect Authorization