PT-2026-102965 · Aisoc · Aisoc

·

CVE-2026-103055

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AiSOC versions 7.5.0 through 11.x
Description The realtime WebSocket and SSE service uses a hard-coded constant for JSON Web Token (JWT) verification when the AISOC REALTIME JWT SECRET environment variable is not configured. This allows unauthenticated attackers to forge subscription tickets using arbitrary tenant identifiers, enabling unauthorized access to cross-tenant live alerts, cases, agent events, and graph updates via the realtime endpoints.
Recommendations Update AiSOC to version 12.0.0 or later. Set the AISOC REALTIME JWT SECRET environment variable to a secure, unique value to ensure proper JWT verification.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103055
GHSA-4M55-XHCM-WJCR

Affected Products

Aisoc