CVE-2026-103053 MEDIUM

CVE-2026-103053: AiSOC 9.0.0 before 12.0.0 Missing Authentication on Actions Service Response-Action API

Vendor Beenuar
Product AiSOC
Weakness CWE-306 · Missing auth
Published September 30, 2026
Last update September 30, 2026

CVSS base score

5.3/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action integrations, submit and approve actions on behalf of arbitrary principals, and dispatch containment actions using vendor credentials.

Key dates

02Disclosure timeline

September 30, 2026 CVE published
September 30, 2026 Record updated

Related vulnerabilities

04Related CVE