


Perceptive Security
SOC/SIEM Consultancy

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerability exists i…
Published:
4 March 2026 at 23:00:00
Alert date:
5 March 2026 at 21:02:45
Source:
nvd.nist.gov
Web Technologies, Identity & Access
OliveTin, a web interface for predefined shell commands, contains an unauthenticated denial-of-service vulnerability in its OAuth2 login flow prior to version 3000.10.3. The vulnerability allows remote attackers to crash the service by sending concurrent requests to /oauth/login, which triggers unsynchronized access to a shared registeredStates map in Go, causing a runtime panic and process termination. This affects installations where OAuth2 authentication is enabled. The issue has been patched in version 3000.10.3.
Technical details
Mitigation steps:
Affected products:
OliveTin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-28789
https://github.com/OliveTin/OliveTin/commit/f044d90d5525c4c8e3f421b32ed7eff771c22d36
https://github.com/OliveTin/OliveTin/security/advisories/GHSA-45m3-398w-m2m9
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
