Description
AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.
Published: 2026-09-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to tenant data and alerts
Action: Apply patch
AI Analysis

Impact

AiSOC versions older than 12.0.0 suffer an authorization bypass in the MSSP module. The flaw allows an authenticated user to call the add_tenants_to_portfolio endpoint and supply arbitrary tenant UUIDs. By doing so, the user can claim unclaimed tenants and view their security alerts, incidents, and posture metrics, effectively bypassing the intended tenant isolation. The vulnerability aligns with CWE‑639, non‑consensual information disclosure via improper authorization.

Affected Systems

This issue affects AiSOC from the vendor beenuar, specifically all releases prior to version 12.0.0. Any installation running AiSOC 10.x or similar earlier versions is potentially impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV. The attack requires valid user credentials; once logged in the attacker can invoke the vulnerable endpoint, adding arbitrary tenants that are not yet claimed. The exploit does not need special network access beyond the normal service reach and thus can be executed as long as an attacker has an authenticated session or has compromised an existing account.

Generated by OpenCVE AI on September 30, 2026 at 07:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the official upgrade to AiSOC 12.0.0 or later to eliminate the flaw.
  • Enforce restriction on the add_tenants_to_portfolio endpoint so that only privileged users can add tenants, and validate tenant ownership before adding.
  • Monitor API usage for add_tenants_to_portfolio calls that associate tenants without prior claim and alert administrators to suspicious activity.

Generated by OpenCVE AI on September 30, 2026 at 07:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.
Title AiSOC 10.0.0 before 12.0.0 Unauthorized Tenant Access via MSSP
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-30T00:19:10.583Z

Reserved: 2026-09-29T23:34:43.511Z

Link: CVE-2026-103054

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T01:16:36.727

Modified: 2026-09-30T01:16:36.727

Link: CVE-2026-103054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:00:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key