Authorization Bypass in OliveTin Web Application by OliveTin
CVE-2026-48709
3.7LOW
What is CVE-2026-48709?
An authorization bypass vulnerability exists in OliveTin, allowing unauthenticated users to access the ValidateArgumentType RPC endpoint without any authentication or authorization checks. This flaw can be exploited to enumerate valid action binding IDs and their argument configurations, posing a significant security risk. The issue has been addressed in the updated version 3000.13.0, which enforces proper authentication mechanisms.
Affected Version(s)
OliveTin < 3000.13.0
