CVE-2026-30233 is an authorization flaw in OliveTin, a web interface for predefined shell commands, affecting versions prior to 3000.11.1. Authenticated users with restricted view permissions can still enumerate action bindings and metadata, including titles, IDs, icons, and argument details, via dashboard and API endpoints, even if command execution is denied. This vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring low privileges, and resulting in high confidentiality impact without affecting integrity or availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3000.11.1CPE matchmatch criteria | cpe:2.3:a:olivetin:olivetin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.