Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4fqm-6fmh-82mq | OliveTin has Unauthenticated Action Termination via KillAction When Guests Must Login |
Tue, 10 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:olivetin:olivetin:*:*:*:*:*:*:*:* |
Fri, 06 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Olivetin
Olivetin olivetin |
|
| Vendors & Products |
Olivetin
Olivetin olivetin |
Thu, 05 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to terminate running actions through KillAction even when authRequireGuestsToLogin: true is enabled. Guests are correctly blocked from dashboard access, but can still call the KillAction RPC directly and successfully stop a running action. This is a broken access control issue that causes unauthorized denial of service against legitimate action executions. This issue has been patched in version 3000.11.0. | |
| Title | OliveTin: Unauthenticated Action Termination via KillAction When Guests Must Login | |
| Weaknesses | CWE-284 CWE-862 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-06T17:57:04.488Z
Reserved: 2026-03-03T14:25:19.244Z
Link: CVE-2026-28790
Updated: 2026-03-06T17:56:50.373Z
Status : Analyzed
Published: 2026-03-05T20:16:16.820
Modified: 2026-03-10T15:29:58.073
Link: CVE-2026-28790
No data.
OpenCVE Enrichment
Updated: 2026-04-16T12:15:35Z
Github GHSA