CVE-2026-82817
Received Received - Intake

Improper Access Control in Dibo Software Diboot Tenant Management API

Vulnerability report for CVE-2026-82817, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulDB

Description

A vulnerability was found in dibo-software diboot 3.8.0. Affected by this issue is some unknown functionality of the file /admin/ of the component Tenant Administrator Management API. Performing a manipulation of the argument tenantId results in improper access controls. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
dibo-software diboost 3.8.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects dibo-software diboot 3.8.0, specifically the Tenant Administrator Management API. It involves improper access controls due to a manipulation of the tenantId argument in the /admin/ file. The issue allows unauthorized remote access to sensitive functions.

Impact Analysis

An attacker could exploit this to gain unauthorized access to tenant administration features, potentially leading to data breaches, unauthorized modifications, or service disruption. The public availability of the exploit increases the risk of real-world attacks.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules. Organizations using this software may face compliance failures, legal penalties, and reputational damage.

Mitigation Strategies

Immediately restrict access to the /admin/ endpoint and validate all tenantId inputs for proper authorization checks. Update or patch the diboot software to the latest version if available. Monitor network traffic for unusual API requests targeting tenant management functions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82817. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart