OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to terminate running actions through KillAction even when authRequireGuestsToLogin: true is enabled. Guests are correctly blocked from dashboard access, but can still call the KillAction RPC directly and successfully stop a running action. This is a broken access control issue that causes unauthorized denial of service against legitimate action executions. This issue has been patched in version 3000.11.0.
Cite this page
CVE-2026-28790. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-28790
Use CWE-284, Olivetin vendor hub and Olivetin product page to widen CVE-2026-28790 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-27626, CVE-2026-30223 and CVE-2026-31817 for nearby disclosures in the same product family.