Five vulnerabilities in AiSOC (the open-source SOC platform) were disclosed today.
The worst one — CVE-2026-103056 (CVSS 9.0) — builds CrowdStrike Real Time Response command strings by interpolating unescaped parameters. Inject a single quote into file_path, path, script_name, or script_args, and you execute arbitrary commands on managed endpoints with SYSTEM or root privileges. The containment tool becomes the attack.
The other four:
- CVE-2026-103055 (CVSS 7.5) — Hard-coded JWT secret for realtime WebSocket/SSE. Any attacker can forge tokens to read cross-tenant live alerts and incidents.
- CVE-2026-103054 (CVSS 7.1) — MSSP tenant takeover. Authenticated users can claim arbitrary tenants and read their security data.
- CVE-2026-103053 — Missing auth on the response-action dispatch endpoint in the default Docker Compose deployment. AISOC_DEV_MODE defaults to enabled, the service token is never generated, so the host-isolation endpoint accepts requests with no credentials.
- CVE-2026-103057 (CVSS 4.3) — Unauthenticated posting to internal realtime event endpoints.
All fixed in AiSOC 12.0.0.
If you're running 5.1.0+: upgrade now, set AISOC_ACTIONS_SERVICE_TOKEN and AISOC_REALTIME_JWT_SECRET, disable AISOC_DEV_MODE.
Full breakdown with root-cause analysis and mitigation checklist:
https://threataft.com/articles/aisoc-mass-disclosure-cve-2026-103056-103055-103054-103053-103057
Top comments (0)