๐Ÿ” CVE Alert

CVE-2026-67439

MEDIUM 4.3

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service/internal/api/api.go StartActionAndWait and StartActionByGetAndWait endpoints return full LogEntry output after execution without enforcing the logs permission, allowing a user with exec permission but logs:false to read action output. This issue is fixed in version 3000.17.0.

CWE CWE-863
Vendor olivetin
Product olivetin
Published Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for olivetin olivetin

Be the first to know when new medium vulnerabilities affecting olivetin olivetin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

OliveTin / OliveTin
< 3000.17.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OliveTin/OliveTin/security/advisories/GHSA-jm28-2wcr-qf3h github.com: https://github.com/OliveTin/OliveTin/commit/e421780c9885aa5024d2f47b4ed4898f2f18eb90 github.com: https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0