๐Ÿ” CVE Alert

CVE-2026-103056

CRITICAL 9.0

AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR

CVSS Score
9.0
EPSS Score
0.0%
EPSS Percentile
0th

AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.

CWE CWE-78
Vendor beenuar
Product aisoc
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for beenuar aisoc

Be the first to know when new critical vulnerabilities affecting beenuar aisoc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

beenuar / AiSOC
7.2.0 < 12.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/beenuar/AiSOC/security/advisories/GHSA-7q37-2wfw-xrx7 github.com: https://github.com/beenuar/AiSOC/commit/dac39723404130312daba15d42d19114f09f75b2 github.com: https://github.com/beenuar/AiSOC/releases/tag/v12.0.0 github.com: https://github.com/beenuar/AiSOC/blob/v11.2.0/services/actions/app/clients/crowdstrike_rtr.py#L273 github.com: https://github.com/beenuar/AiSOC/blob/v11.2.0/services/actions/app/executors/endpoint.py#L442 vulncheck.com: https://www.vulncheck.com/advisories/aisoc-7.2.0-before-12.0.0-command-injection-via-crowdstrike-rtr

Credits

hyderpwn