CVE-2026-103057 Details
Description
AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary events with spoofed tenant identifiers to broadcast malicious content over WebSocket and Redis SSE channels or send unauthorized notifications to registered devices.
A vulnerability allowing authentication bypass has been identified in AiSOC versions 5.1.0 prior to 12.0.0. This issue resides within the realtime service's internal endpoints, specifically POST /internal/agent-event and POST /internal/push. The vulnerability arises because the authentication guard for these endpoints fails to enforce authorization when the internal token is unset, allowing unauthorized users to inject events into any tenant's live stream or send push notifications to registered devices.
To address this vulnerability, update to AiSOC version 12.0.0 or later, where the issue has been fixed. In versions prior to 12.0.0, the internal token must be manually set to ensure proper authentication.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AiSOC | >= 5.1.0, < 12.0.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion