Impact
AiSOC versions older than 12.0.0 suffer an authorization bypass in the MSSP module. The flaw allows an authenticated user to call the add_tenants_to_portfolio endpoint and supply arbitrary tenant UUIDs. By doing so, the user can claim unclaimed tenants and view their security alerts, incidents, and posture metrics, effectively bypassing the intended tenant isolation. The vulnerability aligns with CWE‑639, non‑consensual information disclosure via improper authorization.
Affected Systems
This issue affects AiSOC from the vendor beenuar, specifically all releases prior to version 12.0.0. Any installation running AiSOC 10.x or similar earlier versions is potentially impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV. The attack requires valid user credentials; once logged in the attacker can invoke the vulnerable endpoint, adding arbitrary tenants that are not yet claimed. The exploit does not need special network access beyond the normal service reach and thus can be executed as long as an attacker has an authenticated session or has compromised an existing account.
OpenCVE Enrichment