CVE-2026-27626 is an OS command injection vulnerability in OliveTin, a web interface for invoking predefined shell commands. In versions up to and including 3000.10.0, OliveTin's shell mode safety validation does not treat the password argument type as unsafe, allowing shell metacharacters supplied through a password-typed argument to bypass the intended shell argument safety check and reach command execution. A second, independent flaw affects webhook-extracted JSON values, which can bypass type safety validation entirely before being incorporated into commands executed through sh -c. These flaws allow attacker-controlled input to be interpreted by the shell rather than handled as inert data, resulting in arbitrary command execution on the host running OliveTin.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
password-typed argument can execute arbitrary operating system commands. Through the webhook vector, an unauthenticated attacker can achieve the same outcome when the instance accepts externally sourced webhooks and uses webhook-derived values in Shell mode actions. In deployments where Shell mode is used with webhook-triggered actions, the combined exposure can lead to unauthenticated remote code execution.If you can’t patch tonight, do this now.
sh -c. Require authentication for access paths that can trigger actions, including webhook handling, and avoid deployments using unauthenticated defaults. Restrict webhook exposure to trusted sources using network controls or reverse-proxy allowlisting. Do not use user-supplied password-typed arguments in Shell mode actions, and prevent webhook-derived fields from being templated into shell commands. Where possible, replace shell execution with safer non-shell command invocation patterns.Patch, then assume compromise.
password-typed arguments are subject to the same shell safety restrictions as other dangerous argument types, and to enforce strict type validation and allowlisting for webhook-extracted values before they are inserted into command templates. A more robust fix is to avoid shell-based execution through sh -c and instead invoke commands using argument-array execution semantics that do not permit shell metacharacter interpretation. If no vendor patch is available, apply a source-level fix implementing these controls.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small standalone Python proof-of-concept for CVE-2026-27626 affecting OliveTin. It contains two files: a single exploit script (`CVE-2026.27626.py`) and a detailed `README.md` describing the vulnerability, affected versions, impact, and usage. The exploit is not part of a larger framework. The Python script uses `requests` to interact directly with OliveTin's gRPC-style HTTP API endpoints. Its workflow is simple: it builds a base URL from user-supplied host and port, sends a POST request to `/api/olivetin.api.v1.OliveTinApiService/StartAction` with a crafted JSON body, and injects a shell command into the `db_pass` argument using the pattern `';<cmd>;'`. The script hardcodes the target action binding as `backup_database` and includes supporting arguments `db_user=backup_svc` and `db_name=production`. After triggering execution, it calls `/api/olivetin.api.v1.OliveTinApiService/ExecutionStatus` with the returned execution tracking ID and prints any command output from the response. Main exploit capability: authenticated or exposed remote OS command execution against a vulnerable OliveTin deployment, resulting in arbitrary command execution as the OliveTin process user. The PoC also provides basic output retrieval, making it operational rather than a mere detection script. The README additionally documents a second unauthenticated webhook-based injection vector in OliveTin, but that vector is described only in documentation and is not implemented in the provided code. Notable operational characteristics: TLS verification is disabled, timeout is set to 10 seconds, and the default command is `id`. The exploit assumes the target OliveTin instance is reachable on port 1337 and that the specified action binding and vulnerable argument handling are present. Overall, the repository's purpose is to demonstrate and validate command injection leading to RCE in vulnerable OliveTin Shell mode configurations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.