Junglewise Threat Intelligence

CVE-2026-82818: dibo-software diboot improper access control in tenant resource assignment

CVE-2026-82818 · Severity: medium · CVSS 6.3 · Published 2026-08-31

Executive brief

diboot is a Java-based web application framework used to build enterprise management systems. A vulnerability in the tenant resource assignment feature allows attackers to manipulate the tenantId parameter and bypass access controls, potentially granting unauthorized access to tenant data and resources across different organizations.

Technical details

An improper access control vulnerability exists in the Tenant Resource Assignment Handler component within the /api/iam/tenant/resource endpoint of diboot 3.8.0. The vulnerability stems from inadequate validation of the tenantId parameter, allowing authenticated or unauthenticated attackers to manipulate this parameter and access resources belonging to other tenants. The attack is network-accessible and has been publicly disclosed. No vendor patch is currently available as the vendor did not respond to early disclosure attempts.

Affected products

  • dibo-software diboot 3.8.0

Timeline

  • 2026-08-31: disclosed: Publicly disclosed vulnerability
  • 2026-08-31: advisory

References

Related threats