OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-103055

HIGH · CVSS 7.5 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

AiSOC versions prior to 12.0.0 are vulnerable due to a hard-coded constant used for JWT verification, which can be exploited when the AISOC_REALTIME_JWT_SECRET environment variable is not configured. This flaw allows unauthenticated attackers to forge subscription tickets, granting them unauthorized access to cross-tenant live alerts, cases, agent events, and graph updates via real-time endpoints. Organizations utilizing affected versions should prioritize remediation to mitigate the risk of data exposure and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103055
Severity
HIGH
CVSS
7.5
EPSS
0.40%

Original NVD Description

AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.