THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jm28-2wcr-qf3h (medium) — OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

[GHSA] GHSA-jm28-2wcr-qf3h (medium) — OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

medgithub_advisoriesPublished 2026-07-30

GHSA-jm28-2wcr-qf3h Severity: medium CVE: CVE-2026-67439

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

## Summary

The synchronous execution RPCs `StartActionAndWait` and `StartActionByGetAndWait` return the full `LogEntry` for the just-executed action without checking whether the caller is allowed to read that action's logs.

OliveTin's ACL model separ

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jm28-2wcr-qf3h