PT-2026-102963 · Aisoc · Aisoc
CVSS v3.1
5.4
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AiSOC versions 9.0.0 through 11.9.9
Description
Authentication is not enforced on the response-action API endpoints when
AISOC DEV MODE is enabled and AISOC ACTIONS SERVICE TOKEN is empty within the default Docker Compose deployment. This allows unauthenticated attackers to list response-action integrations, submit and approve actions as arbitrary principals, and dispatch containment actions using vendor credentials.Recommendations
Update AiSOC to version 12.0.0 or later.
Disable
AISOC DEV MODE in production environments.
Ensure AISOC ACTIONS SERVICE TOKEN is properly configured and not left empty.Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aisoc