Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action integrations, submit and approve actions on behalf of arbitrary principals, and dispatch containment actions using vendor credentials. | |
| Title | AiSOC 9.0.0 before 12.0.0 Missing Authentication on Actions Service Response-Action API | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-30T00:19:09.978Z
Reserved: 2026-09-29T23:34:43.109Z
Link: CVE-2026-103053
No data.
No data.
No data.
OpenCVE Enrichment
No data.