CVE-2026-30225 affects OliveTin versions prior to 3000.11.1, where a low-privileged authenticated user can exploit an authentication context confusion in the RestartAction function. This allows them to execute shell commands they are not authorized to run, effectively bypassing Access Control List (ACL) restrictions due to the system falling back to a guest user with broader permissions. The vulnerability has a CVSS score of 5.3 (Medium), indicating a network-based attack with low complexity, requiring no user interaction, and resulting in low integrity impact. While it allows for unauthorized command execution, the impact on confidentiality and availability is minimal. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also very low, suggesting limited public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3000.11.1CPE matchmatch criteria | cpe:2.3:a:olivetin:olivetin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.