VYPR
Vendor

Dibo Software

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2026-70557MedAug 6, 2026
    risk 0.42cvss 6.5epss 0.00

    diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those values for all rows, with no field or entity allowlist. The only guard, relatedDataSecurityCheck(), returns true unconditionally,…

  • CVE-2026-82818MedAug 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in dibo-software diboot 3.8.0. This affects an unknown part of the file /api/iam/tenant/resource of the component Tenant Resource Assignment Handler. Executing a manipulation of the argument tenantId can lead to improper access controls. The attack…

  • CVE-2026-82817MedAug 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in dibo-software diboot 3.8.0. Affected by this issue is some unknown functionality of the file /admin/ of the component Tenant Administrator Management API. Performing a manipulation of the argument tenantId results in improper access controls. The…

  • CVE-2026-82816MedAug 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in dibo-software diboot 3.8.0. Affected by this vulnerability is an unknown functionality of the file /api/ai-session/ of the component AI Session Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The…