CVE-2026-103054
published 2026-09-30CVE-2026-103054: AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to…
PriorityP344high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.22%
11.7th percentile
AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| beenuar | aisoc | >= 10.0.0 < 12.0.0 | 12.0.0 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own.
ghsa_unreviewed·2026-09-30
CVE-2026-103054 [HIGH] CWE-639 AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own.
AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.
VulDB
beenuar AiSOC up to 11.x MSSP module tenant_uuids authorization
vuldb·2026-09-30·CVSS 7.1
CVE-2026-103054 [HIGH] beenuar AiSOC up to 11.x MSSP module tenant_uuids authorization
A vulnerability was found in beenuar AiSOC up to 11.x. It has been classified as critical. This vulnerability affects unknown code of the component MSSP module. Performing a manipulation of the argument tenant_uuids results in authorization bypass.
This vulnerability was named CVE-2026-103054. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/beenuar/AiSOC/blob/v11.2.0/services/api/app/api/v1/endpoints/mssp.py#L1073-L1110https://github.com/beenuar/AiSOC/commit/151264a8b846db55099e5e0f4d76c388e8df4a92https://github.com/beenuar/AiSOC/releases/tag/v12.0.0https://github.com/beenuar/AiSOC/security/advisories/GHSA-mcg9-8pxf-j98vhttps://www.vulncheck.com/advisories/aisoc-10.0.0-before-12.0.0-unauthorized-tenant-access-via-mssphttps://github.com/beenuar/AiSOC/security/advisories/GHSA-mcg9-8pxf-j98v
2026-09-30
Published