CVE-2026-30223 is a high-severity authentication bypass vulnerability affecting OliveTin versions prior to 3000.11.1. When JWT authentication is configured, the system fails to enforce the audience (aud) claim, allowing validly signed tokens intended for other services to authenticate users. This flaw carries a CVSS score of 8.8 (High), indicating that an unauthenticated attacker can achieve high confidentiality, integrity, and availability impacts over the network with low complexity. There is no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB. Community discussion is minimal, with only one mention identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3000.11.1CPE matchmatch criteria | cpe:2.3:a:olivetin:olivetin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.