CVE-2026-103053 Details
Description
AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action integrations, submit and approve actions on behalf of arbitrary principals, and dispatch containment actions using vendor credentials.
A vulnerability exists in AiSOC versions 9.0.0 prior to 12.0.0, where the actions service fails to enforce authentication on critical response-action API endpoints. This issue arises when AISOC_DEV_MODE is enabled and the AISOC_ACTIONS_SERVICE_TOKEN is empty, which is the default configuration in the Docker Compose deployment. As a result, unauthenticated attackers can access the response-action integrations, submit and approve actions on behalf of any principal, and execute containment actions using vendor credentials.
The vulnerability has been fixed in AiSOC version 12.0.0. To address the issue, update to this version and ensure that the AISOC_ACTIONS_SERVICE_TOKEN is set in the environment. If using a version prior to 12.0.0, manually configure the token and disable AISOC_DEV_MODE before deploying.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/beenuar/AiSOC/security/advisories/GHSA-g4h7-p63q-r8r4 | CISA-ADP | AdvisoryBundleExploitRemedyVendor |
| https://github.com/beenuar/AiSOC/blob/v11.2.0/services/actions/app/security/authz.py#L104-L121 | [email protected] | Source CodeVendor |
| https://github.com/beenuar/AiSOC/commit/dac39723404130312daba15d42d19114f09f75b2 | [email protected] | Source CodeVendor |
| https://github.com/beenuar/AiSOC/releases/tag/v12.0.0 | [email protected] | Release NotesVendor |
| https://github.com/beenuar/AiSOC/security/advisories/GHSA-g4h7-p63q-r8r4 | [email protected] | AdvisoryBundleExploitRemedyVendor |
| https://www.vulncheck.com/advisories/aisoc-9.0.0-before-12.0.0-missing-authentication-on-actions-service-response-action-api | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| beenuar AiSOC | >= 9.0.0, < 12.0.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion