CVE-2026-103054 Details
Description
AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.
A vulnerability exists in AiSOC versions prior to 12.0.0, specifically within the MSSP module. This authorization bypass allows authenticated users, including those with only viewer privileges, to add arbitrary tenants to their portfolios. The vulnerability arises because the system does not verify whether the user has the right to claim the tenant. Once a tenant is added, the user can access the tenant's security alerts, incidents, and posture metrics without consent. The issue can be exploited by sending tenant UUIDs to the 'add_tenants_to_portfolio' endpoint, effectively claiming unassigned tenants and reading their sensitive data.
The vulnerability has been fixed in AiSOC version 12.0.0. In this update, the process of adding tenants to a portfolio now requires the tenant to have invited the organization, ensuring that consent is obtained before any data can be accessed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/beenuar/AiSOC/security/advisories/GHSA-mcg9-8pxf-j98v | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/beenuar/AiSOC/blob/v11.2.0/services/api/app/api/v1/endpoints/mssp.py#L1073-L1110 | [email protected] | Source CodeVendor |
| https://github.com/beenuar/AiSOC/commit/151264a8b846db55099e5e0f4d76c388e8df4a92 | [email protected] | Source CodeVendor |
| https://github.com/beenuar/AiSOC/releases/tag/v12.0.0 | [email protected] | Release NotesVendor |
| https://github.com/beenuar/AiSOC/security/advisories/GHSA-mcg9-8pxf-j98v | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/aisoc-10.0.0-before-12.0.0-unauthorized-tenant-access-via-mssp | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Beenuar AiSOC | >= 10.0.0, < 12.0.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion