CVE-2026-103055 Details
Description
AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.
A vulnerability exists in AiSOC versions 7.5.0 prior to 12.0.0, where a hard-coded constant is used for JSON Web Token (JWT) verification in the real-time WebSocket and Server-Sent Events (SSE) service. This issue arises when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can exploit this by forging subscription tickets with arbitrary tenant identifiers, allowing them to access cross-tenant live alerts, cases, agent events, and graph updates through the real-time endpoints.
To address this vulnerability, update to AiSOC version 12.0.0 or later, where the issue has been fixed. In versions prior to 12.0.0, ensure that the AISOC_REALTIME_JWT_SECRET environment variable is set to a secure value before deploying the application.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/beenuar/AiSOC/blob/v11.2.0/services/realtime/src/auth.ts#L51-L59 | [email protected] | Source CodeVendor |
| https://github.com/beenuar/AiSOC/commit/2f0e954f2febecb3720e6eadb017546c5d121c43 | [email protected] | Source CodeVendor |
| https://github.com/beenuar/AiSOC/releases/tag/v12.0.0 | [email protected] | Release NotesVendor |
| https://github.com/beenuar/AiSOC/security/advisories/GHSA-4m55-xhcm-wjcr | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/aisoc-7.5.0-before-12.0.0-authentication-bypass-via-hard-coded-jwt-secret | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Beenuar AiSOC | >= 7.5.0, <= 11.2.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion