CVE-2026-103054
Received Received - Intake

Authorization Bypass in AiSOC MSSP Module

Vulnerability report for CVE-2026-103054, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
beenuar aisoc to 12.0.0 (exc)
beenuar aisoc 12.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103054 is an authorization bypass vulnerability in AiSOC versions before 12.0.0. It allows authenticated users to add arbitrary tenants to portfolios they own by submitting tenant UUIDs via the add_tenants_to_portfolio endpoint. This grants unauthorized access to the target tenant's security alerts, incidents, and posture metrics without consent.

Detection Guidance

To detect this vulnerability, check for unauthorized tenant attachments in AiSOC logs. Look for POST requests to /mssp/organizations/current/tenants or /mssp/children endpoints with tenant UUIDs not owned by the requester. Verify if any user accounts have unexpectedly gained MSSP organization ownership or portfolio access.

Impact Analysis

Attackers can exploit this to read sensitive security data from other tenants, including alerts, incidents, and posture metrics. It enables cross-tenant data exposure, allowing unauthorized access to confidential information. The attack requires only authentication and no special privileges, making it easy to repeat.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and privacy, such as GDPR and HIPAA, due to unauthorized access to sensitive security data. It undermines tenant isolation and consent mechanisms, leading to potential legal and regulatory penalties.

Mitigation Strategies

Immediately upgrade AiSOC to version 12.0.0 or later. Review all MSSP portfolio configurations for unauthorized tenant attachments. Revoke any suspicious organization ownerships and audit access logs for unauthorized data access. Ensure tenant consent is enforced via mssp_parent_invite settings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103054. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart