Authorization Bypass in OliveTin Web Application by OliveTin
CVE-2026-48709

3.7LOW

Key Information:

Vendor

Olivetin

Status
Vendor
CVE Published:
15 June 2026

What is CVE-2026-48709?

An authorization bypass vulnerability exists in OliveTin, allowing unauthenticated users to access the ValidateArgumentType RPC endpoint without any authentication or authorization checks. This flaw can be exploited to enumerate valid action binding IDs and their argument configurations, posing a significant security risk. The issue has been addressed in the updated version 3000.13.0, which enforces proper authentication mechanisms.

Affected Version(s)

OliveTin < 3000.13.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.