CVE-2026-103057: Beenuar Aisoc
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary events with spoofed tenant identifiers to broadcast malicious content over WebSocket and Redis SSE channels or send unauthorized notifications to registered devices.
Affected products
- Beenuar Aisoc: from 5.1.0, before 12.0.0 (fixed in 12.0.0)
Published 2026-09-30. Last modified 2026-09-30.