PT-2026-23617 · Olivetin · Olivetin

Zwique

·

Published

2026-03-05

·

Updated

2026-03-25

·

CVE-2026-30233

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OliveTin versions prior to 3000.11.1
Description OliveTin has an authorization issue where authenticated users with insufficient permissions (view: false) can access metadata related to actions through the dashboard and API endpoints. Specifically, the backend does not properly enforce view permissions when generating responses for dashboard and action binding information. This allows restricted users to retrieve details like action titles, IDs, icons, and argument metadata, even though they are not authorized to execute those actions. The vulnerable API endpoints include '/api/GetDashboard' and '/api/GetActionBinding'. The vulnerable parameter is bindingId in the '/api/GetActionBinding' endpoint. The issue stems from a failure to enforce the IsAllowedView() function when constructing these responses.
Recommendations Update OliveTin to version 3000.11.1 or later.

Exploit

Fix

Information Disclosure

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30233
GHSA-JF73-858C-54PG
GO-2026-4629
SUSE-SU-2026:1042-1

Affected Products

Olivetin