CVE-2026-103055
published 2026-09-30CVE-2026-103055: AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET…
PriorityP352high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.40%
32.5th percentile
AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| beenuar | aisoc | >= 7.5.0 < 12.0.0 | 12.0.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set.
ghsa_unreviewed·2026-09-30
CVE-2026-103055 [HIGH] CWE-321 AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set.
AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.
VulDB
beenuar AiSOC up to 11.x Realtime WebSocket And Sse Service improper authentication
vuldb·2026-09-30·CVSS 7.5
CVE-2026-103055 [HIGH] beenuar AiSOC up to 11.x Realtime WebSocket And Sse Service improper authentication
A vulnerability categorized as problematic has been discovered in beenuar AiSOC up to 11.x. The affected element is an unknown function of the component Realtime WebSocket And Sse Service. The manipulation results in improper authentication.
This vulnerability is identified as CVE-2026-103055. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/beenuar/AiSOC/blob/v11.2.0/services/realtime/src/auth.ts#L51-L59https://github.com/beenuar/AiSOC/commit/2f0e954f2febecb3720e6eadb017546c5d121c43https://github.com/beenuar/AiSOC/releases/tag/v12.0.0https://github.com/beenuar/AiSOC/security/advisories/GHSA-4m55-xhcm-wjcrhttps://www.vulncheck.com/advisories/aisoc-7.5.0-before-12.0.0-authentication-bypass-via-hard-coded-jwt-secrethttps://github.com/beenuar/AiSOC/security/advisories/GHSA-4m55-xhcm-wjcr
2026-09-30
Published