PT-2026-102965 · Aisoc · Aisoc
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AiSOC versions 7.5.0 through 11.x
Description
The realtime WebSocket and SSE service uses a hard-coded constant for JSON Web Token (JWT) verification when the
AISOC REALTIME JWT SECRET environment variable is not configured. This allows unauthenticated attackers to forge subscription tickets using arbitrary tenant identifiers, enabling unauthorized access to cross-tenant live alerts, cases, agent events, and graph updates via the realtime endpoints.Recommendations
Update AiSOC to version 12.0.0 or later.
Set the
AISOC REALTIME JWT SECRET environment variable to a secure, unique value to ensure proper JWT verification.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aisoc