CVE-2026-103057

Source
https://cve.org/CVERecord?id=CVE-2026-103057
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103057.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-103057
Aliases
  • GHSA-mqjp-pcpr-7c37
Published
2026-09-30T00:19:12Z
Modified
2026-10-02T03:30:46Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
AiSOC 5.1.0 before 12.0.0 Missing Authentication on Realtime Service Internal Endpoints
Details

AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary events with spoofed tenant identifiers to broadcast malicious content over WebSocket and Redis SSE channels or send unauthorized notifications to registered devices.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-306"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103057.json"
}
References

Affected packages

Git / github.com/beenuar/aisoc

Affected ranges

Type
GIT
Repo
https://github.com/beenuar/aisoc
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "5.1.0"
        },
        {
            "fixed":  "12.0.0"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103057.json"