CVE-2026-103056 PUBLISHED

AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR

Assigner: VulnCheck
Reserved: 29.09.2026 Published: 30.09.2026 Updated: 30.09.2026

AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor beenuar
Product AiSOC
Versions Default: unaffected
  • affected from 7.2.0 to 12.0.0 (excl.)

Credits

  • hyderpwn finder

References

Problem Types

  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE