CVE-2026-103057

Published: Set 30, 2026 Last Modified: Set 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,3
Attack Vector: adjacent
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 4,3
Attack Vector: adjacent_network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none

Description

AI Translation Available

AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary events with spoofed tenant identifiers to broadcast malicious content over WebSocket and Redis SSE channels or send unauthorized notifications to registered devices.

306

Missing Authentication for Critical Function

Draft
Common Consequences
Security Scopes Affected:
Access Control Other
Potential Impacts:
Gain Privileges Or Assume Identity Varies By Context
Applicable Platforms
Technologies: Cloud Computing, ICS/OT
View CWE Details
https://github.com/beenuar/AiSOC/blob/v11.2.0/services/realtime/src/index.ts#L6…
https://github.com/beenuar/AiSOC/commit/2f0e954f2febecb3720e6eadb017546c5d121c43
https://github.com/beenuar/AiSOC/releases/tag/v12.0.0
https://github.com/beenuar/AiSOC/security/advisories/GHSA-mqjp-pcpr-7c37
https://www.vulncheck.com/advisories/aisoc-5.1.0-before-12.0.0-missing-authenti…