在 AiSOC 12.0.0 之前的版本中,MSSP 模块存在一个权限绕过漏洞,允许已认证的用户向自己拥有的投资组合(portfolio)中添加任意租户(tenant)。攻击者可以通过 add_tenants_to_portfolio 接口提交租户的 UUID,从而非法获取未分配的租户,并在未经其同意的情况下读取这些租户的安全告警、安全事件和合规性指标等敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103056 | 9.0 CRITICAL | AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR |
| CVE-2026-103055 | 7.5 HIGH | AiSOC 7.5.0 before 12.0.0 Authentication Bypass via Hard-coded JWT Secret |
| CVE-2026-103053 | 5.4 MEDIUM | AiSOC 9.0.0 before 12.0.0 Missing Authentication on Actions Service Response-Action API |
| CVE-2026-103057 | 4.3 MEDIUM | AiSOC 5.1.0 before 12.0.0 Missing Authentication on Realtime Service Internal Endpoints |
No comments yet