VYPR
Moderate severityNVD Advisory· Published Jul 29, 2026· Updated Jul 30, 2026

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

CVE-2026-67439

Description

OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service/internal/api/api.go StartActionAndWait and StartActionByGetAndWait endpoints return full LogEntry output after execution without enforcing the logs permission, allowing a user with exec permission but logs:false to read action output. This issue is fixed in version 3000.17.0.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/OliveTin/OliveTinGo
< 0.0.0-20260708085316-e421780c98850.0.0-20260708085316-e421780c9885

Affected products

1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.