在 AiSOC 7.5.0 至 12.0.0(不含)版本中,当未设置 环境变量时,系统会在实时 WebSocket 和 SSE(Server-Sent Events)服务中使用硬编码的常量进行 JWT(JSON Web Token)验证。未授权的攻击者可以伪造任意租户标识符的订阅票据(subscription tickets),从而通过实时接口访问跨租户的实时告警、案例、代理事件和图更新数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103056 | 9.0 CRITICAL | AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR |
| CVE-2026-103054 | 7.1 HIGH | AiSOC 10.0.0 before 12.0.0 Unauthorized Tenant Access via MSSP |
| CVE-2026-103053 | 5.4 MEDIUM | AiSOC 9.0.0 before 12.0.0 Missing Authentication on Actions Service Response-Action API |
| CVE-2026-103057 | 4.3 MEDIUM | AiSOC 5.1.0 before 12.0.0 Missing Authentication on Realtime Service Internal Endpoints |
No comments yet