OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-103056

CRITICAL · CVSS 9 EPSS 1.46% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Versions 7.2.0 through 12.0.0 of AiSOC are vulnerable to a command injection flaw in the actions service, allowing authenticated users to exploit unescaped parameters in specific scripts. This vulnerability can lead to the execution of arbitrary commands with SYSTEM or root privileges on managed endpoints, posing a critical risk to system integrity. Organizations using affected versions should prioritize patching to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103056
Severity
CRITICAL
CVSS
9
EPSS
1.46%

Original NVD Description

AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.