CVE-2026-103054

Source
https://cve.org/CVERecord?id=CVE-2026-103054
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103054.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-103054
Aliases
  • GHSA-mcg9-8pxf-j98v
Published
2026-09-30T00:19:10Z
Modified
2026-10-02T03:31:06Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
AiSOC 10.0.0 before 12.0.0 Unauthorized Tenant Access via MSSP
Details

AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-639"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103054.json"
}
References

Affected packages

Git / github.com/beenuar/aisoc

Affected ranges

Type
GIT
Repo
https://github.com/beenuar/aisoc
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "10.0.0"
        },
        {
            "fixed":  "12.0.0"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v10.*
v10.0.0
v11.*
v11.0.0
v11.1.0
v11.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103054.json"