PatchSiren

diboot CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH diboot CVE published 2026-08-06

CVE-2026-70557

CVE-2026-70557 debrief based on the supplied source corpus. The vulnerability in diboot-core's POST /common/load-related-data endpoint allows unauthorized data exposure. The endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those values for all rows, with no field or entity allowlist. This issue enables the exposure of secret fields such as IamAccount.authSe [truncated]