CVE-2026-103057
published 2026-09-30CVE-2026-103057: AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and…
PriorityP428medium4.3CVSS 3.1
AVAACLPRNUINSUCNILAN
EPSS
0.25%
15.4th percentile
AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary events with spoofed tenant identifiers to broadcast malicious content over WebSocket and Redis SSE channels or send unauthorized notifications to registered devices.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| beenuar | aisoc | >= 5.1.0 < 12.0.0 | 12.0.0 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
beenuar AiSOC 5.1.0/11.x Realtime Service /internal/agent-event improper authorization
vuldb·2026-09-30·CVSS 4.3
CVE-2026-103057 [MEDIUM] beenuar AiSOC 5.1.0/11.x Realtime Service /internal/agent-event improper authorization
A vulnerability identified as problematic has been detected in beenuar AiSOC 5.1.0/11.x. The impacted element is an unknown function of the file /internal/agent-event of the component Realtime Service. This manipulation causes improper authorization.
This vulnerability is tracked as CVE-2026-103057. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
GHSA
AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push.
ghsa_unreviewed·2026-09-30
CVE-2026-103057 [MEDIUM] CWE-306 AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push.
AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary events with spoofed tenant identifiers to broadcast malicious content over WebSocket and Redis SSE channels or send unauthorized notifications to registered devices.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/beenuar/AiSOC/blob/v11.2.0/services/realtime/src/index.ts#L681-L691https://github.com/beenuar/AiSOC/commit/2f0e954f2febecb3720e6eadb017546c5d121c43https://github.com/beenuar/AiSOC/releases/tag/v12.0.0https://github.com/beenuar/AiSOC/security/advisories/GHSA-mqjp-pcpr-7c37https://www.vulncheck.com/advisories/aisoc-5.1.0-before-12.0.0-missing-authentication-on-realtime-service-internal-endpointshttps://github.com/beenuar/AiSOC/security/advisories/GHSA-mqjp-pcpr-7c37
2026-09-30
Published