CyberRota Analysis
AI-GeneratedThe MSSP module in AiSOC versions prior to 12.0.0 is vulnerable to an authorization bypass, enabling authenticated users to add unauthorized tenants to their portfolios. This flaw allows attackers to exploit the add_tenants_to_portfolio endpoint, gaining access to sensitive security alerts, incidents, and posture metrics of unclaimed tenants. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized data access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.