AiSOC 5.1.0 至 12.0.0 之前的版本中,实时服务的内部端点 POST /internal/agent-event 和 POST /internal/push 存在身份验证绕过漏洞。攻击者可以通过伪造租户标识符,发布任意事件,从而通过 WebSocket 和 Redis SSE 通道广播恶意内容,或向已注册的设备发送未经授权的通知。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103056 | 9.0 CRITICAL | AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR |
| CVE-2026-103055 | 7.5 HIGH | AiSOC 7.5.0 before 12.0.0 Authentication Bypass via Hard-coded JWT Secret |
| CVE-2026-103054 | 7.1 HIGH | AiSOC 10.0.0 before 12.0.0 Unauthorized Tenant Access via MSSP |
| CVE-2026-103053 | 5.4 MEDIUM | AiSOC 9.0.0 before 12.0.0 Missing Authentication on Actions Service Response-Action API |
No comments yet