Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Olivetin

First CVE: Aug 13, 2025Active for: 1 yearTotal CVEs: 11
39.8
VTI Score
Medium

Olivetin is a focused task-execution and automation tool that exposes a command-interface to authorized users, concentrating its vulnerability exposure in a single product across a relatively narrow but notably prominent deployment footprint. The recurring weakness classes—improper access control, OS command injection, missing and incorrect authorization, and uncontrolled resource consumption—reflect the inherent risks of a system that parses and executes user-supplied commands, and vulnerabilities here carry a meaningful share that reach serious severity. Defenders deploying this tool should enforce strict network isolation, apply role-based access controls at the application layer, and treat input validation and authorization logic as critical hardening points; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
5.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Olivetin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 13, 2025
11 months ago
Most Recent CVE
Mar 11, 2026
135 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-27626CRITICAL
OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety check (`checkShellArgumentSafety`)
Feb 25, 20269.933NONO
CVE-2026-30223HIGH
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using either "authJwtPubKeyPath" (local R
Mar 6, 20268.829NONO
CVE-2026-31817HIGH
OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature is enabled, OliveTin persists execution log entries to disk.
Mar 10, 20268.528NONO
CVE-2026-28790HIGH
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to terminate running actions through K
Mar 5, 20267.526NONO
CVE-2026-28789HIGH
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerability exists in OliveTin’s OAuth2
Mar 5, 20267.526NONO
CVE-2026-28342HIGH
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthenticated users to trigger excessive
Mar 5, 20267.524NONO
CVE-2025-50946MEDIUM
OS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/arguments.go.
Aug 13, 20256.523NONO
CVE-2026-32102MEDIUM
OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution events and action output to auth
Mar 11, 20266.522NONO
CVE-2026-30233MEDIUM
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authorization flaw in OliveTin allows authenticated users with view: false p
Mar 6, 20264.318NONO
CVE-2026-30225MEDIUM
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication context confusion vulnerability in RestartAction allows a low
Mar 6, 20264.318NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
45%
45%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low7 (63.6%)
High0 (0.0%)
None4 (36.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Olivetin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Olivetin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Olivetin's Products

View all 2 CNAs →

Top CWEs