CVE-2026-103053: Beenuar Aisoc
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action integrations, submit and approve actions on behalf of arbitrary principals, and dispatch containment actions using vendor credentials.
Affected products
- Beenuar Aisoc: from 9.0.0, before 12.0.0 (fixed in 12.0.0)
Published 2026-09-30. Last modified 2026-09-30.