Aller au contenu

Fiche vulnérabilité

CVE-2026-32102 : faille moyenne olivetin olivetin (CVSS 6.5)

Description

OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution events and action output to authenticated dashboard subscribers without enforcing per-action authorization. A low-privileged authenticated user can receive output from actions they are not allowed to view, resulting in broken access control and sensitive information disclosure.

En bref

Sévérité
Moyenne (CVSS 6.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
11 mars 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • olivetin olivetin

Références

Rechercher une autre vulnérabilité dans la base CVE