Junglewise Threat Intelligence

CVE-2026-82817: dibo-software diboot Tenant Administrator improper access control

CVE-2026-82817 · Severity: medium · CVSS 6.3 · Published 2026-08-31

Executive brief

diboot is an admin management API used to control tenant access in multi-tenant systems. A flaw in the /admin/ endpoint allows attackers to bypass access controls by manipulating the tenantId parameter, potentially enabling unauthorized access to administrative functions across different tenants without authentication.

Technical details

The vulnerability is an improper access control flaw in the Tenant Administrator Management API exposed at the /admin/ endpoint of diboot 3.8.0. The root cause is insufficient validation of the tenantId parameter passed to the TenantController, allowing attackers to manipulate it to access resources across tenant boundaries. The attack is network-reachable and may require low-level authentication depending on the endpoint's exposure. A successful exploit grants an attacker the ability to read and potentially modify administrative configuration for other tenants. No patch is currently available; the vendor did not respond to early disclosure.

Affected products

  • dibo-software diboot 3.8.0

Timeline

  • 2026-08-31: disclosed
  • other: Exploit made public

References

Related threats