THREAT OPS › Threat News › [GHSA] GHSA-jm28-2wcr-qf3h (medium) — OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
[GHSA] GHSA-jm28-2wcr-qf3h (medium) — OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
GHSA-jm28-2wcr-qf3h Severity: medium CVE: CVE-2026-67439
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
## Summary
The synchronous execution RPCs `StartActionAndWait` and `StartActionByGetAndWait` return the full `LogEntry` for the just-executed action without checking whether the caller is allowed to read that action's logs.
OliveTin's ACL model separ
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-67439cve
Original source: https://github.com/advisories/GHSA-jm28-2wcr-qf3h