Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OliveTin — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in OliveTin, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for OliveTin, a containerized alternative to webmin designed to allow users to execute bash commands via a web interface, categorized under common weakness enumeration types affecting web applications and system utilities. The collection includes reported security flaws, configuration weaknesses, and execution-related risks discovered in public databases and advisories over the past five years, covering versions released since its initial introduction to the market. Here, you can track vendor-specific advisory notifications to stay informed about emerging threats, analyze recurring weakness classes that impact similar command-execution interfaces, and review the product’s historical vulnerability landscape to assess its security posture and remediation trends. This resource is intended for security professionals, system administrators, and developers who need a consolidated view of known issues affecting OliveTin deployments. By providing structured access to vulnerability details without overwhelming the reader with raw data, the page facilitates informed decision-making regarding patching, configuration hardening, and risk assessment. The information is sourced from widely recognized vulnerability trackers and public security reports, ensuring a comprehensive yet curated overview. Users can explore how specific flaws have been addressed over time, identify patterns in reported incidents, and evaluate the overall stability of the software from a security perspective. This approach supports proactive maintenance and helps organizations understand the historical context of security incidents related to this product.

Vendor: OliveTin

CVE ID Title CVSS Severity Published
CVE-2026-53541 OliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input Filtering CWE-20 4.3 Medium 2026-08-21
CVE-2026-67439 OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output CWE-863 4.3 Medium 2026-07-29
CVE-2026-67438 OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check CWE-78 6.6 Medium 2026-07-29
CVE-2026-67437 OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) CWE-400 7.5 High 2026-07-29
CVE-2026-48709 OliveTin: ValidateArgumentType API Endpoint Missing Authentication Allows Action and Argument Enumeration CWE-862 3.7 Low 2026-06-15
CVE-2026-48708 OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination CWE-362 7.5 High 2026-06-15
CVE-2026-32102 OliveTin Unauthorized Action Output Disclosure via EventStream CWE-284 8.8AI High AI 2026-03-11
CVE-2026-31817 OliveTin's unsafe parsing of UniqueTrackingId can be used to write files CWE-22 8.5 High 2026-03-10
CVE-2026-30233 OliveTin: View permission not being checked when returning dashboards CWE-200 6.5 Medium 2026-03-06
CVE-2026-30225 OliveTin: RestartAction always runs actions as guest CWE-441 5.3 Medium 2026-03-06
CVE-2026-30223 OliveTin: JWT Audience Validation Bypass in Local Key and HMAC Modes CWE-287 8.8 High 2026-03-06
CVE-2026-30224 OliveTin: Session Fixation - Logout Fails to Invalidate Server-Side Session CWE-384 5.4 Medium 2026-03-06
CVE-2026-28790 OliveTin: Unauthenticated Action Termination via KillAction When Guests Must Login CWE-284 7.5 High 2026-03-05
CVE-2026-28789 OliveTin: Unauthenticated DoS via concurrent map writes in OAuth2 state handling CWE-362 7.5 High 2026-03-05
CVE-2026-28342 OliveTin: Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API Endpoint CWE-770 7.5 High 2026-03-05
CVE-2026-27626 OliveTin vulnerable to OS Command Injection via `password` argument type and webhook JSON extraction bypasses shell safety checks CWE-78 10.0 Critical 2026-02-25

All 16 known CVE vulnerabilities affecting OliveTin with full Chinese analysis, references, and POCs where available.