Junglewise Threat Intelligence

CVE-2026-82816: dibo-software diboot authorization bypass in AI Session Endpoint

CVE-2026-82816 · Severity: medium · CVSS 6.3 · Published 2026-08-31

Executive brief

diboot is a web application framework. The AI Session Endpoint (/api/ai-session/) contains an authorization bypass vulnerability that allows attackers to access protected functionality remotely without proper authentication. An attacker could bypass access controls to view or modify sensitive data through the AI session management interface.

Technical details

The vulnerability is an authorization bypass flaw in the AI Session Endpoint component (/api/ai-session/) of diboot 3.8.0, affecting the AiSessionController. The vulnerability allows remote attackers to bypass authentication or authorization checks and access restricted functionality. The attack requires network access to the endpoint but does not require prior authentication. The exploit has been publicly disclosed. No vendor patch is currently available as the vendor did not respond to the initial disclosure.

Affected products

  • dibo-software diboot 3.8.0

Timeline

  • 2026-08-31: disclosed: Public disclosure of exploit
  • 2026-08-31: advisory: CVE-2026-82816 published

References

Related threats