What is CVE-2026-67437?
CVE-2026-67437 is a vulnerability in OliveTin from versions 3000.0.0 to 3000.17.0 where the OAuth2 login handler stores per-login states in the registeredStates map without expiration, deletion, or binding. It affects the service providing web interface access to shell commands, and exploitation may pose security risks. Updating OliveTin to the latest version is recommended.
Azərbaycanca: CVE-2026-67437 OliveTin-in 3000.0.0-dən 3000.17.0 versiyalarına qədər OAuth2 login handler-də per-login state-lərin registeredStates map-də expire, delete və ya bound edilmədən saxlanmasına görə yaranan zəiflikdir. Veb interfeysə girişi təmin edən xidmətə təsir edir, istismar halında təhlükəsizlik riskləri yarada bilər. OliveTin-i ən son versiyaya yeniləmək tövsiyə olunur.
FAQ1
Which component of OliveTin does CVE-2026-67437 affect?
This vulnerability affects the OAuth2 login handler component of OliveTin. Specifically, it impacts the service providing web interface access due to per-login states being stored in the registeredStates map without expiration, deletion, or binding.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.