Impact
The flaw resides in the Tenant Administrator Management API of dibo-software diboot. By manipulating the tenantId parameter in the /admin/ endpoint, an attacker can bypass the intended access controls. This improper validation allows remote users to invoke functions that should be restricted to legitimate tenant administrators, effectively granting unauthorized administrative capabilities.
Affected Systems
The affected product is dibo-software diboot version 3.8.0. The vulnerability appears in the /admin/ component of the Tenant Administrator Management API, which receives the tenantId argument. No other product versions are listed as impacted in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, but the EPSS score is not available and the vulnerability is not listed in CISA's KEV catalogue. The public exploit demonstrates that an attacker can initiate the attack remotely by sending a crafted request to the /admin/ endpoint. Because the vulnerability has been disclosed publicly and the vendor did not respond, the risk of exploitation remains tangible, especially for organizations still running version 3.8.0 without mitigation.
OpenCVE Enrichment