Shell Command Access Vulnerability in OliveTin by OliveTin
CVE-2026-67439

4.3MEDIUM

Key Information:

Vendor

Olivetin

Status
Vendor
CVE Published:
29 July 2026

What is CVE-2026-67439?

OliveTin prior to version 3000.17.0 contains a vulnerability in its web interface that allows users with execution permissions to access sensitive action output logs without proper permission checks. Specifically, the service's endpoints, StartActionAndWait and StartActionByGetAndWait, inadvertently expose log entries to unauthorized users who have been restricted from viewing logs. This oversight may lead to sensitive information being disclosed, compromising the application's integrity. The issue has been resolved in version 3000.17.0.

Affected Version(s)

OliveTin < 3000.17.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.