Five vulnerabilities disclosed in open-source SOC platform AiSOC
Five vulnerabilities were disclosed in the open-source SOC platform AiSOC. The most severe, CVE-2026-103056 (CVSS 9.0), lets attackers execute arbitrary commands with SYSTEM or root privileges on managed endpoints via unescaped parameters.
- CVE-2026-103056 (CVSS 9.0): injection into CrowdStrike RTR strings enables RCE as SYSTEM/root
- CVE-2026-103055 (CVSS 7.5): hard-coded JWT secret allows forged tokens and cross-tenant alert access
- CVE-2026-103054 (CVSS 7.1): authenticated users can claim arbitrary MSSP tenants
- CVE-2026-103053: default Docker Compose deployment leaves host-isolation endpoint unauthenticated
Read next
Security