← Vulnerability feed

Vulnerability record · CVE-2026-32102 · published 11 March 2026

CVE-2026-32102: Olivetin improper access control vulnerability

OOlivetin · Olivetin

OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution events and action output to authenticated dashboard subscribers without enforcing per-action authorization. A low-privileged authenticated user can receive output from actions they are not allowed to view, resulting in broken access control and sensitive information disclosure.

7.1 CVSS 4.0 High EPSS 0.48% · top 61.1% CWE-284 · Improper access controlCWE-863 · Incorrect authorization
7.1CVSS 4.0 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution events and action output to authenticated dashboard subscribers without enforcing per-action authorization. A low-privileged authenticated user can receive output from actions they are not allowed to view, resulting in broken access control and sensitive information disclosure.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-32102 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-27626Olivetin os command injection vulnerabilityOliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety chec…EPSS 0.65%8.8CVE-2026-30223Olivetin improper authentication vulnerabilityOliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using eith…EPSS 0.31%8.5CVE-2026-31817Olivetin path traversal vulnerabilityOliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature is enabled, OliveTin persists …EPSS 0.92%7.5CVE-2026-28789Olivetin race condition vulnerabilityOliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerabili…EPSS 0.47%7.5CVE-2026-28790Olivetin improper access control vulnerabilityOliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to term…EPSS 0.78%7.5CVE-2026-28342Olivetin uncontrolled resource consumption vulnerabilityOliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthentic…EPSS 0.78%6.5CVE-2025-50946Olivetin os command injection vulnerabilityOS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/arguments.go.EPSS 1.3%5.4CVE-2026-30224Olivetin insufficient session expiration vulnerabilityOliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not revoke server-side sessions wh…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2026-32102), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.