MEDIUMVulnerability

CVE-2026-82817

A vulnerability was found in dibo-software diboot 3.8.0. Affected by this issue is some unknown functionality of the file /admin/ of the component Tenant Administrator Management API. Performing a manipulation of the argument tenantId results in improper access controls. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

severity
MEDIUM
score
6.3
epss_score
0.00201
cve_id
CVE-2026-82817
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
published_at
2026-08-31T18:17:24.650
last_modified
2026-09-02T15:17:43.447
epss_percentile
0.10045

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (2)

[Weakness]Incorrect Privilege Assignment
[Weakness]Improper Access Control

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82817 — Ninja Signal Threat Intelligence | Ninja Signal