Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.3

OliveTin: Privilege Escalation via Authentication Context Confusion

CVE-2026-30225 GHSA-p443-p7w5-2f7f GHSA-p443-p7w5-2f7f
Summary

A security weakness in OliveTin's RestartAction feature allows a low-privileged user to access actions they shouldn't be able to run, potentially executing unauthorized commands. This issue has been fixed in OliveTin version 3000.11.1. Update to the latest version to protect your system.

What to do
  • Update github.com olivetin to version 0.0.0-20260305000458-cb46a597b246.
  • Update olivetin github.com/olivetin/olivetin to version 0.0.0-20260305000458-cb46a597b246.
Affected software
VendorProductAffected versionsFix available
github.com olivetin <= 0.0.0-20260305000458-cb46a597b246 0.0.0-20260305000458-cb46a597b246
olivetin github.com/olivetin/olivetin <= 0.0.0-20260305000458-cb46a597b246 0.0.0-20260305000458-cb46a597b246
olivetin olivetin <= 3000.11.1
Original title
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication context confusion vulnerability in RestartAction allows a low‑privileged authe...
Original description
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication context confusion vulnerability in RestartAction allows a low‑privileged authenticated user to execute actions they are not permitted to run. RestartAction constructs a new internal connect.Request without preserving the original caller’s authentication headers or cookies. When this synthetic request is passed to StartAction, the authentication resolver falls back to the guest user. If the guest account has broader permissions than the authenticated caller, this results in privilege escalation and unauthorized command execution. This vulnerability allows a low‑privileged authenticated user to bypass ACL restrictions and execute arbitrary configured shell actions. This issue has been patched in version 3000.11.1.
nvd CVSS3.1 5.3
Vulnerability type
CWE-250
CWE-441
Published: 6 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026