CVE-2026-32102

OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution events and action output to authenticated dashboard subscribers without enforcing per-action authorization. A low-privileged authenticated user can receive output from actions they are not allowed to view, resulting in broken access control and sensitive information disclosure.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:olivetin:olivetin:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-11 21:16

Updated : 2026-03-17 15:34


NVD link : CVE-2026-32102

Mitre link : CVE-2026-32102

CVE.ORG link : CVE-2026-32102


JSON object : View

Products Affected

olivetin

  • olivetin
CWE
CWE-284

Improper Access Control

CWE-863

Incorrect Authorization