CVE-CVE-2026-27626
Severity
CRITICAL
CVSS Score
9.9
Description
OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety check (`checkShellArgumentSafety`) blocks several dangerous argument types but not `password`. A user supplying a `password`-typed argument can inject shell metacharacters that execute arbitrary OS commands. A second independent vector allows unauthenticated RCE via webhook-extracted JSON values that skip type safety checks entirely before reaching `sh ...
PoCs for CVE-CVE-2026-27626
Enigm-Writeup
SQL Injection
1
abdelhakimgaferNetworkSec
2026-09-23