{"data":{"id":"f2928076-11c5-40b3-aee7-87c5831b9fc6","title":"CVE-2026-103055: AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE…","summary":"AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers, gaining access to cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103055","publishedAt":"2026-09-30T01:16:36.880Z","cveId":"CVE-2026-103055","cweIds":["CWE-321"],"cvssScore":"7.5","cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["AiSOC"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"AiSOC hard-coded JWT verification secret in realtime WebSocket and SSE service","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00405,"epssCheckedAt":"2026-10-10T02:58:44.792Z","kevDateAdded":null,"advisoryAliases":["GHSA-j6w5-vmvx-vgrp"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:43:06.687Z","patchAvailable":null,"disclosureDate":"2026-09-30T01:16:36.880Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null}}