๐Ÿ” CVE Alert

CVE-2026-103054

HIGH 7.1

AiSOC 10.0.0 before 12.0.0 Unauthorized Tenant Access via MSSP

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.

CWE CWE-639
Vendor beenuar
Product aisoc
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for beenuar aisoc

Be the first to know when new high vulnerabilities affecting beenuar aisoc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

beenuar / AiSOC
10.0.0 < 12.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/beenuar/AiSOC/security/advisories/GHSA-mcg9-8pxf-j98v github.com: https://github.com/beenuar/AiSOC/commit/151264a8b846db55099e5e0f4d76c388e8df4a92 github.com: https://github.com/beenuar/AiSOC/releases/tag/v12.0.0 github.com: https://github.com/beenuar/AiSOC/blob/v11.2.0/services/api/app/api/v1/endpoints/mssp.py#L1073-L1110 vulncheck.com: https://www.vulncheck.com/advisories/aisoc-10.0.0-before-12.0.0-unauthorized-tenant-access-via-mssp

Credits

hyderpwn