CVE-2026-103056
published 2026-09-30CVE-2026-103056: AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings…
PriorityP266critical9CVSS 3.1
AVNACLPRLUIRSCCHIHAH
EPSS
1.46%
72.7th percentile
AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| beenuar | aisoc | >= 7.2.0 < 12.0.0 | 12.0.0 |
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
beenuar AiSOC up to 11.x Actions Service crowdstrike_rtr.py file_path/path/script_name/script_args command injection
vuldb·2026-09-30·CVSS 9.0
CVE-2026-103056 [CRITICAL] beenuar AiSOC up to 11.x Actions Service crowdstrike_rtr.py file_path/path/script_name/script_args command injection
A vulnerability was found in beenuar AiSOC up to 11.x. It has been rated as very critical. Impacted is an unknown function of the file crowdstrike_rtr.py of the component Actions Service. The manipulation of the argument file_path/path/script_name/script_args leads to command injection.
This vulnerability is referenced as CVE-2026-103056. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
GHSA
AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action paramet
ghsa_unreviewed·2026-09-30
CVE-2026-103056 [CRITICAL] CWE-78 AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action paramet
AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/beenuar/AiSOC/blob/v11.2.0/services/actions/app/clients/crowdstrike_rtr.py#L273https://github.com/beenuar/AiSOC/blob/v11.2.0/services/actions/app/executors/endpoint.py#L442https://github.com/beenuar/AiSOC/commit/dac39723404130312daba15d42d19114f09f75b2https://github.com/beenuar/AiSOC/releases/tag/v12.0.0https://github.com/beenuar/AiSOC/security/advisories/GHSA-7q37-2wfw-xrx7https://www.vulncheck.com/advisories/aisoc-7.2.0-before-12.0.0-command-injection-via-crowdstrike-rtrhttps://github.com/beenuar/AiSOC/security/advisories/GHSA-7q37-2wfw-xrx7
2026-09-30
Published