Description
AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action integrations, submit and approve actions on behalf of arbitrary principals, and dispatch containment actions using vendor credentials.
Published: 2026-09-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted action execution
Action: Immediate Patch
AI Analysis

Impact

AiSOC releases 9.0.0 through 11.9.9 do not enforce authentication on the response‑action API when the application runs in development mode and the service token is unset. This weakness allows any requester to list existing action integrations, submit new actions, approve approved actions, and dispatch containment operations as if they were an authorized principal. The attacker’s ability to perform these functions effectively gives them the capability to trigger arbitrary actions and modify system state, which can lead to data tampering, unauthorized data access, and disruption of services.

Affected Systems

The affected product is AiSOC from the vendor Beenuar. Versions 9.0.0, 10.x, 11.x—and any prior to the 12.0.0 release—have been identified as vulnerable. Users running these releases in a Docker Compose environment with AISOC_DEV_MODE enabled and an empty AISOC_ACTIONS_SERVICE_TOKEN are at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is internal to the installation environment—commonly a development or staging network—where AISOC runs with default Developer Mode settings. An attacker who can reach the affected endpoints without authentication can exploit the missing check to perform privileged operations.

Generated by OpenCVE AI on September 30, 2026 at 07:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade AiSOC to version 12.0.0 or later to apply the vendor fix.
  • Disable AISOC_DEV_MODE and set a non‑empty value for AISOC_ACTIONS_SERVICE_TOKEN in the Docker Compose and configuration files where the application is deployed.
  • Restrict network access to the response‑action API endpoints until the update or configuration change is in place.

Generated by OpenCVE AI on September 30, 2026 at 07:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action integrations, submit and approve actions on behalf of arbitrary principals, and dispatch containment actions using vendor credentials.
Title AiSOC 9.0.0 before 12.0.0 Missing Authentication on Actions Service Response-Action API
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-30T13:57:54.515Z

Reserved: 2026-09-29T23:34:43.109Z

Link: CVE-2026-103053

cve-icon Vulnrichment

Updated: 2026-09-30T13:57:50.561Z

cve-icon NVD

Status : Received

Published: 2026-09-30T01:16:36.563

Modified: 2026-09-30T14:17:26.307

Link: CVE-2026-103053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:00:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function