CyberRota Analysis
AI-GeneratedAiSOC versions prior to 12.0.0 are vulnerable due to a hard-coded constant used for JWT verification, which can be exploited when the AISOC_REALTIME_JWT_SECRET environment variable is not configured. This flaw allows unauthenticated attackers to forge subscription tickets, granting them unauthorized access to cross-tenant live alerts, cases, agent events, and graph updates via real-time endpoints. Organizations utilizing affected versions should prioritize remediation to mitigate the risk of data exposure and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.