← Vulnerability feed

Vulnerability record · CVE-2026-30223 · published 6 March 2026

CVE-2026-30223: Olivetin improper authentication vulnerability

OOlivetin · Olivetin

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using either "authJwtPubKeyPath" (local RSA public key) or "authJwtHmacSecret" (HMAC secret), the configured audience value (authJwtAud) is not enforced during token parsing. As a result, validly signed JWT tokens with an incorrect aud claim are accepted for authentication. This allows authentication using tokens intended for a different audience/service. This issue has been patched in version 3000.11.1.

8.8 CVSS 3.1 High EPSS 0.31% · top 78.6% CWE-287 · Improper authenticationCWE-345 · Insufficient verification of data authenticity
8.8CVSS 3.1 base score
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using either "authJwtPubKeyPath" (local RSA public key) or "authJwtHmacSecret" (HMAC secret), the configured audience value (authJwtAud) is not enforced during token parsing. As a result, validly signed JWT tokens with an incorrect aud claim are accepted for authentication. This allows authentication using tokens intended for a different audience/service. This issue has been patched in version 3000.11.1.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-30223 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-27626Olivetin os command injection vulnerabilityOliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety chec…EPSS 0.65%8.5CVE-2026-31817Olivetin path traversal vulnerabilityOliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature is enabled, OliveTin persists …EPSS 0.92%7.5CVE-2026-28789Olivetin race condition vulnerabilityOliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerabili…EPSS 0.47%7.5CVE-2026-28790Olivetin improper access control vulnerabilityOliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to term…EPSS 0.78%7.5CVE-2026-28342Olivetin uncontrolled resource consumption vulnerabilityOliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthentic…EPSS 0.78%7.1CVE-2026-32102Olivetin improper access control vulnerabilityOliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution e…EPSS 0.48%6.5CVE-2025-50946Olivetin os command injection vulnerabilityOS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/arguments.go.EPSS 1.3%5.4CVE-2026-30224Olivetin insufficient session expiration vulnerabilityOliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not revoke server-side sessions wh…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2026-30223), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.