CVE-2026-103055
Received Received - Intake

AiSOC JWT Forgery via Hard-Coded Secret in Realtime Service

Vulnerability report for CVE-2026-103055, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
beenuar aisoc 7.5.0
beenuar aisoc 11.2.0
beenuar aisoc From 7.5.0 (inc) to 12.0.0 (exc)
beenuar aisoc 11.9.9
beenuar aisoc 12.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

AiSOC versions 7.5.0 to 11.9.9 used a hard-coded secret for JWT verification in realtime WebSocket and SSE services when the AISOC_REALTIME_JWT_SECRET environment variable was not set. Attackers could forge subscription tickets with arbitrary tenant IDs to access cross-tenant live alerts, cases, agent events, and graph updates without authentication.

Detection Guidance

Check if AiSOC versions 7.5.0 through 11.9.9 are running by inspecting the version in logs or deployment files. Verify if the AISOC_REALTIME_JWT_SECRET environment variable is unset or uses a hard-coded default. Monitor realtime WebSocket/SSE connections for unauthorized tenant access or suspicious ticket submissions.

Impact Analysis

Unauthenticated attackers could access sensitive real-time data across tenants, including live alerts, cases, agent events, and graph updates. This could lead to unauthorized disclosure of confidential information like investigation details and approval prompts.

Compliance Impact

This vulnerability could violate GDPR's data confidentiality requirements and HIPAA's safeguards for protected health information by enabling unauthorized access to sensitive real-time data across tenants. Compliance may be compromised due to potential data breaches.

Mitigation Strategies

Upgrade AiSOC to version 12.0.0 or later immediately. Ensure the AISOC_REALTIME_JWT_SECRET environment variable is set to a strong, unique value. Verify that the realtime service rejects connections when secrets are unset by testing fail-closed behavior.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103055. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart