<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T01:28:40.576704+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275135</id>
    <title>EUVD-2026-275135</title>
    <updated>2026-10-07T01:28:40.640511+00:00</updated>
    <content>EUVD-2026-275135</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275135"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30225</id>
    <title>fkie_cve-2026-30225</title>
    <updated>2026-10-07T01:28:40.640570+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication context confusion vulnerability in RestartAction allows a low‑privileged authenticated user to execute actions they are not permitted to run. RestartAction constructs a new internal connect.Request without preserving the original caller’s authentication headers or cookies. When this synthetic request is passed to StartAction, the authentication resolver falls back to the guest user. If the guest account has broader permissions than the authenticated caller, this results in privilege escalation and unauthorized command execution. This vulnerability allows a low‑privileged authenticated user to bypass ACL restrictions and execute arbitrary configured shell actions. This issue has been patched in version 3000.11.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-30225"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p443-p7w5-2f7f</id>
    <title>GHSA-p443-p7w5-2f7f — OliveTin's RestartAction always runs actions as guest</title>
    <updated>2026-10-07T01:28:40.640637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/OliveTin/OliveTin</p>
<p>### Summary
An authentication context confusion vulnerability in RestartAction allows a low‑privileged authenticated user to execute actions they are not permitted to run.</p>
<p>RestartAction constructs a new internal connect.Request without preserving the original caller’s authentication headers or cookies. When this synthetic request is passed to StartAction, the authentication resolver falls back to the guest user. If the guest account has broader permissions than the authenticated caller, this results in privilege escalation and unauthorized command execution.</p>
<p>This vulnerability allows a low‑privileged authenticated user to bypass ACL restrictions and execute arbitrary configured shell actions.</p>
<p>### Details
Affected files:</p>
<p>service/internal/api/api.go</p>
<p>service/internal/auth/authcheck.go</p>
<p>Relevant code in RestartAction:</p>
<p>```
return api.StartAction(ctx, &amp;connect.Request[apiv1.StartActionRequest]{
    Msg: &amp;apiv1.StartActionRequest{
        BindingId:        execReqLogEntry.GetBindingId(),
        UniqueTrackingId: req.Msg.ExecutionTrackingId,
    },
})
```
Authentication in StartAction:
```
authenticatedUser := auth.UserFromApiCall(ctx, req, api.cfg)
```
Issue:</p>
<p>1. RestartAction creates a new connect.Request object.</p>
<p>2. The new request does not preserve caller headers or cookies.</p>
<p>3. UserFromApiCall() attempts to resolve the user from the request.</p>
<p>4. Because authentication headers are missing, it falls back to the guest user.</p>
<p>5. If guest.exec = true while the original caller…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p443-p7w5-2f7f"/>
  </entry>
</feed>
