Description
A vulnerability has been found in dibo-software diboot 3.8.0. Affected by this vulnerability is an unknown functionality of the file /api/ai-session/ of the component AI Session Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-31
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in dibo-software’s diboot 3.8.0 allows attackers to manipulate the /api/ai-session/ endpoint, resulting in an authorization bypass that can grant unauthorized access to protected resources. This flaw stems from improper access control (CWE-285) and the improper handling of sensitive data (CWE-639). The result is that anyone with the correct endpoint can access AI session data without proper credentials.

Affected Systems

The flaw affects dibo-software’s diboot product, specifically version 3.8.0. No other versions are listed as impacted, and the disclosed vulnerability targets the web interface exposing /api/ai-session/.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the attack can be launched remotely. EPSS data is not available, yet the exploit has been publicly disclosed and may be used by adversaries. Although not listed in CISA’s KEV catalog, the remote nature and lack of a defensive measure make the vulnerability potentially exploitable.

Generated by OpenCVE AI on August 31, 2026 at 20:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑released patch or upgrade diboot to a version that resolves the authorization bypass.
  • If a patch is not yet available, restrict access to the /api/ai-session/ endpoint by enforcing strict authentication and authorization checks or by disabling the endpoint entirely.
  • Monitor application logs for unexpected or unauthenticated access attempts to the /api/ai-session/ endpoint and assess the use of intrusion detection.

Generated by OpenCVE AI on August 31, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in dibo-software diboot 3.8.0. Affected by this vulnerability is an unknown functionality of the file /api/ai-session/ of the component AI Session Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title dibo-software diboot AI Session Endpoint ai-session authorization
First Time appeared Dibo-software
Dibo-software diboot
Weaknesses CWE-285
CWE-639
CPEs cpe:2.3:a:dibo-software:diboot:*:*:*:*:*:*:*:*
Vendors & Products Dibo-software
Dibo-software diboot
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Dibo-software Diboot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T18:41:30.170Z

Reserved: 2026-08-31T05:33:07.233Z

Link: CVE-2026-82816

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T18:17:24.467

Modified: 2026-08-31T19:17:22.807

Link: CVE-2026-82816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T20:15:05Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key