CVE-2026-103054
Last modified
CVE-2026-103054 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent..
Description
AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| beenuar | AiSOC | >= 10.0.0, < 12.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-103054?
How severe is CVE-2026-103054?
How do I fix CVE-2026-103054?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-103048URL redirection to untrusted site ('open redirect') vulnerab…6.1
- CVE-2026-103049Improper neutralization of input during web page generation …6.1
- CVE-2026-10305Out-of-bounds read vulnerability in Samsung Open Source rlot…6.1
- CVE-2026-103050Improper neutralization of input during web page generation …6.1
- CVE-2026-103051Improper neutralization of input during web page generation …6.1
- CVE-2026-103053AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentic…5.4
- CVE-2026-103055AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant…7.5
- CVE-2026-103056AiSOC versions 7.2.0 before 12.0.0 contain a command injecti…9
- CVE-2026-103057AiSOC versions 5.1.0 before 12.0.0 contain an authentication…4.3
- CVE-2026-103063Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2026-103064Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2026-103067Cross-Site Request Forgery (CSRF) vulnerability in Memberful…8
Are you affected by CVE-2026-103054?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
