Impact
AiSOC releases 9.0.0 through 11.9.9 do not enforce authentication on the response‑action API when the application runs in development mode and the service token is unset. This weakness allows any requester to list existing action integrations, submit new actions, approve approved actions, and dispatch containment operations as if they were an authorized principal. The attacker’s ability to perform these functions effectively gives them the capability to trigger arbitrary actions and modify system state, which can lead to data tampering, unauthorized data access, and disruption of services.
Affected Systems
The affected product is AiSOC from the vendor Beenuar. Versions 9.0.0, 10.x, 11.x—and any prior to the 12.0.0 release—have been identified as vulnerable. Users running these releases in a Docker Compose environment with AISOC_DEV_MODE enabled and an empty AISOC_ACTIONS_SERVICE_TOKEN are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is internal to the installation environment—commonly a development or staging network—where AISOC runs with default Developer Mode settings. An attacker who can reach the affected endpoints without authentication can exploit the missing check to perform privileged operations.
OpenCVE Enrichment