CVE-2026-103056 Details
Description
AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.
A command injection vulnerability has been identified in AiSOC versions 7.2.0 prior to 12.0.0. This vulnerability exists within the actions service, specifically in the CrowdStrike Real-Time Response (RTR) command execution process. The issue arises from unescaped user-supplied parameters being interpolated into command strings, which are then executed on managed endpoints with SYSTEM or root privileges. Authenticated users can exploit this by injecting single quotes into certain parameters to manipulate the command execution.
Users are advised to update to AiSOC version 12.0.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/beenuar/AiSOC/security/advisories/GHSA-7q37-2wfw-xrx7 | CISA-ADP | AdvisoryExploitRemedyTechnical AnalysisVendor |
| https://github.com/beenuar/AiSOC/blob/v11.2.0/services/actions/app/clients/crowdstrike_rtr.py#L273 | [email protected] | Source CodeVendor |
| https://github.com/beenuar/AiSOC/blob/v11.2.0/services/actions/app/executors/endpoint.py#L442 | [email protected] | Source CodeVendor |
| https://github.com/beenuar/AiSOC/commit/dac39723404130312daba15d42d19114f09f75b2 | [email protected] | Issue TrackingTechnical AnalysisVendor |
| https://github.com/beenuar/AiSOC/releases/tag/v12.0.0 | [email protected] | Release NotesVendor |
| https://github.com/beenuar/AiSOC/security/advisories/GHSA-7q37-2wfw-xrx7 | [email protected] | AdvisoryExploitRemedyTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/aisoc-7.2.0-before-12.0.0-command-injection-via-crowdstrike-rtr | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Beenuar AiSOC | >= 7.2.0, <= 11.2.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion