当在默认 Docker Compose 部署中启用了 AISOC_DEV_MODE 且 AISOC_ACTIONS_SERVICE_TOKEN 为空时,AiSOC 9.0.0 至 12.0.0 版本(不含 12.0.0)未能对 response-action API 端点实施身份验证。未经验证的攻击者可以列出响应操作集成,代表任意主体提交和批准操作,并使用供应商凭证派遣遏制操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103056 | 9.0 CRITICAL | AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR |
| CVE-2026-103055 | 7.5 HIGH | AiSOC 7.5.0 before 12.0.0 Authentication Bypass via Hard-coded JWT Secret |
| CVE-2026-103054 | 7.1 HIGH | AiSOC 10.0.0 before 12.0.0 Unauthorized Tenant Access via MSSP |
| CVE-2026-103057 | 4.3 MEDIUM | AiSOC 5.1.0 before 12.0.0 Missing Authentication on Realtime Service Internal Endpoints |
No comments yet