Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in dibo-software diboot 3.8.0. Affected by this vulnerability is an unknown functionality of the file /api/ai-session/ of the component AI Session Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | dibo-software diboot AI Session Endpoint ai-session authorization | |
| First Time appeared |
Dibo-software
Dibo-software diboot |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:dibo-software:diboot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dibo-software
Dibo-software diboot |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-31T18:41:30.170Z
Reserved: 2026-08-31T05:33:07.233Z
Link: CVE-2026-82816
No data.
Status : Received
Published: 2026-08-31T18:17:24.467
Modified: 2026-08-31T18:17:24.467
Link: CVE-2026-82816
No data.
OpenCVE Enrichment
No data.