CVE-2026-103053
published 2026-09-30CVE-2026-103053: AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and…
PriorityP336medium5.4CVSS 3.1
AVAACLPRNUINSUCLILAN
EPSS
0.24%
13.5th percentile
AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action integrations, submit and approve actions on behalf of arbitrary principals, and dispatch containment actions using vendor credentials.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| beenuar | aisoc | >= 9.0.0 < 12.0.0 | 12.0.0 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
beenuar AiSOC up to 11.9.9 Response-Action API improper authentication
vuldb·2026-09-30·CVSS 5.4
CVE-2026-103053 [MEDIUM] beenuar AiSOC up to 11.9.9 Response-Action API improper authentication
A vulnerability was found in beenuar AiSOC up to 11.9.9 and classified as critical. This affects an unknown part of the component Response-Action API. Such manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2026-103053. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Com
ghsa_unreviewed·2026-09-30
CVE-2026-103053 [MEDIUM] CWE-306 AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Com
AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action integrations, submit and approve actions on behalf of arbitrary principals, and dispatch containment actions using vendor credentials.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/beenuar/AiSOC/blob/v11.2.0/services/actions/app/security/authz.py#L104-L121https://github.com/beenuar/AiSOC/commit/dac39723404130312daba15d42d19114f09f75b2https://github.com/beenuar/AiSOC/releases/tag/v12.0.0https://github.com/beenuar/AiSOC/security/advisories/GHSA-g4h7-p63q-r8r4https://www.vulncheck.com/advisories/aisoc-9.0.0-before-12.0.0-missing-authentication-on-actions-service-response-action-apihttps://github.com/beenuar/AiSOC/security/advisories/GHSA-g4h7-p63q-r8r4
2026-09-30
Published