OliveTin (a web UI for running predefined shell commands) contains an authentication context confusion flaw in RestartAction prior to 3000.11.1. RestartAction creates a new internal connect.Request but fails to preserve the original caller’s authentication headers/cookies. When this synthetic request is forwarded to StartAction, the authentication resolver cannot associate it with the initiating authenticated user and instead falls back to the guest identity. If the guest account is configured with broader permissions than the initiating low-privileged user, the action authorization check is effectively performed under the guest context, enabling the caller to bypass ACL restrictions and execute configured shell actions they are not permitted to run.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a small standalone Python 3 exploit repository: exploit.py is the only code file, requirements.txt specifies requests, and README.md documents the affected OliveTin behavior and usage. The script accepts a user-supplied OliveTin base URL and optional local-auth cookie, then posts JSON to OliveTin mux API routes. Its check mode calls WhoAmI and GetDashboard, enumerates action bindings recursively, and highlights arguments using password, raw_string_multiline, or checkbox types, which the documented OliveTin type-safety logic does not validate. Its exploit mode invokes StartActionAndWait with caller-selected action arguments and constructs quote-breakout shell injection payloads for single-, double-, or unquoted template contexts. It also contains a focused RestartAction test for CVE-2026-30225, an auth-context loss issue fixed in OliveTin 3000.11.1; the repository notes that some <=3000.10.x handlers forward an empty binding ID and therefore cannot re-run actions. The main practical chain is insecure guest execution permissions plus an injectable shell-based action, producing unauthenticated command execution at the OliveTin process privilege level, documented as root on OliveTin 3000.10.0 in the Enigma environment.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.