CVE-2026-31817 is a high-severity directory traversal vulnerability affecting OliveTin versions prior to 3000.11.2. When the 'saveLogs' feature is enabled, an attacker can manipulate the 'UniqueTrackingId' in API requests to write files to arbitrary locations on the filesystem, potentially leading to system compromise. Rated 8.5 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L), this vulnerability is remotely exploitable with low privileges and no user interaction, impacting system integrity. There is currently no evidence of active exploitation, nor are public exploit codes available, and community discussion remains minimal. Organizations using affected versions should upgrade to 3000.11.2 immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3000.11.2CPE matchmatch criteria | cpe:2.3:a:olivetin:olivetin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.