PT-2026-24467 · Olivetin · Olivetin

Iconnnjka

·

Published

2026-03-10

·

Updated

2026-03-25

·

CVE-2026-31817

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions OliveTin versions prior to 3000.11.2
Description OliveTin provides access to predefined shell commands through a web interface. When the saveLogs feature is enabled, OliveTin persists execution log entries to disk. The filename for these logs is constructed using the UniqueTrackingId field from the StartAction API request. This value is not properly validated or sanitized, allowing an attacker to use directory traversal sequences, such as ../../../, to write files to arbitrary locations on the filesystem. The StartAction API endpoint accepts the UniqueTrackingId variable without validation.
Recommendations Update to version 3000.11.2 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31817
GHSA-364Q-W7VH-VHPC
GO-2026-4670
SUSE-SU-2026:1042-1

Affected Products

Olivetin