---
id: CVE-2026-103054
title: >-
  AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in
  the MSSP module that allows authenticated users to add arbitrary tenants to
  portfolios they own
summary: >-
  AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in
  the MSSP module that allows authenticated users to add arbitrary tenants to
  portfolios they own. Attackers can submit tenant UUIDs via the
  add_tenants_to_portf…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-639
vendor: beenuar
product: AiSOC
affected:
  - AiSOC >= 10.0.0 < 12.0.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T01:16:36.727'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103054'
references:
  - url: >-
      https://github.com/beenuar/AiSOC/blob/v11.2.0/services/api/app/api/v1/endpoints/mssp.py#L1073-L1110
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/beenuar/AiSOC/commit/151264a8b846db55099e5e0f4d76c388e8df4a92
    label: disclosure@vulncheck.com
  - url: 'https://github.com/beenuar/AiSOC/releases/tag/v12.0.0'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/beenuar/AiSOC/security/advisories/GHSA-mcg9-8pxf-j98v'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/aisoc-10.0.0-before-12.0.0-unauthorized-tenant-access-via-mssp
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T00:53:47.829Z'
---

## Overview

AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
