CVE-2026-103057 MEDIUM

CVE-2026-103057: AiSOC 5.1.0 before 12.0.0 Missing Authentication on Realtime Service Internal Endpoints

Vendor Beenuar
Product AiSOC
Weakness CWE-306 · Missing auth
Published September 30, 2026
Last update September 30, 2026

CVSS base score

5.3/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary events with spoofed tenant identifiers to broadcast malicious content over WebSocket and Redis SSE channels or send unauthorized notifications to registered devices.

Key dates

02Disclosure timeline

September 30, 2026 CVE published
September 30, 2026 Record updated