Sceawere

Vulnerability Detail

CVE-2026-82818UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Improper Access Control in diboot

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
13h ago
Vendor
dibo-software
Product
diboot
Attack Type
Improper Access Controls
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in dibo-software diboot 3.8.0. This affects an unknown part of the file /api/iam/tenant/resource of the component Tenant Resource Assignment Handler. Executing a manipulation of the argument tenantId can lead to improper access controls. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-08-31T19:17:22.940Z",
  "pubdate": "2026-08-31T19:17:22.940Z",
  "executiveSummary": "The vulnerability identified in dibo-software diboot version 3.8.0 involves a critical flaw in the Tenant Resource Assignment Handler, specifically within the /api/iam/tenant/resource endpoint.\nThis vulnerability is classified as an improper access control issue, enabling unauthorized actors to manipulate resource assignments by tampering with the tenantId argument.\nThe flaw exists within a key administrative component responsible for managing multi-tenant data segmentation, posing a severe risk of unauthorized data access, cross-tenant information disclosure, and potential privilege escalation.\nThe vulnerability is remotely exploitable, requiring no complex conditions other than network connectivity to the affected endpoint.\nGiven that the vulnerability has been publicly disclosed and the vendor has remained unresponsive, the risk of exploitation by malicious actors is significant, necessitating immediate proactive defensive measures by system administrators to restrict access to the affected URI and monitor for anomalous traffic patterns.",
  "technicalDetails": "The vulnerability resides within the Tenant Resource Assignment Handler, specifically manifesting in the processing logic of the /api/iam/tenant/resource API endpoint.\nThe root cause is an insecure implementation of authorization checks related to the tenantId parameter. When processing requests to this endpoint, the system fails to adequately validate whether the authenticated user or the requesting session has the requisite authorization to assign or modify resources for the target tenant specified in the input.\nAn attacker can exploit this by intercepting and manipulating the tenantId parameter in a crafted HTTP request sent to the /api/iam/tenant/resource endpoint. By supplying a target tenantId, an attacker can bypass intended segmentation logic, effectively performing unauthorized operations on resources belonging to other tenants.\nThe attack flow proceeds as follows: First, the attacker identifies a valid session or authentication token. Second, the attacker crafts a malicious request targeting the /api/iam/tenant/resource URI. Third, the attacker injects an arbitrary or unintended tenantId value into the request body or query string. Finally, the server-side component processes the request without performing a strict server-side validation of the requester's permissions against the target tenant identifier, resulting in the successful execution of an unauthorized assignment or access operation.\nThis represents a failure in the application's access control matrix, where the security boundary between different tenants is not strictly enforced at the functional level. Because the vulnerability is remotely exploitable, an adversary with network access to the API can perform these manipulations without needing physical access or internal network presence.\nThe post-exploitation impact includes the potential for full unauthorized access to tenant-specific resources, which could lead to sensitive data breaches, modification of tenant configuration, or a total breakdown of multi-tenant isolation, thereby allowing an attacker to manipulate the security posture of the software for malicious objectives."
}
CVE-2026-82818: Improper Access Control in diboot (MEDIUM Severity, CVSS: 6.3) - Sceawere