๐Ÿ” CVE Alert

CVE-2026-103055

HIGH 7.5

AiSOC 7.5.0 before 12.0.0 Authentication Bypass via Hard-coded JWT Secret

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.

CWE CWE-321
Vendor beenuar
Product aisoc
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for beenuar aisoc

Be the first to know when new high vulnerabilities affecting beenuar aisoc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

beenuar / AiSOC
7.5.0 < 12.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/beenuar/AiSOC/security/advisories/GHSA-4m55-xhcm-wjcr github.com: https://github.com/beenuar/AiSOC/commit/2f0e954f2febecb3720e6eadb017546c5d121c43 github.com: https://github.com/beenuar/AiSOC/releases/tag/v12.0.0 github.com: https://github.com/beenuar/AiSOC/blob/v11.2.0/services/realtime/src/auth.ts#L51-L59 vulncheck.com: https://www.vulncheck.com/advisories/aisoc-7.5.0-before-12.0.0-authentication-bypass-via-hard-coded-jwt-secret

Credits

hyderpwn