Cyber & AI intelligence
Wasteland.
Briefs indexed2938
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-103056 2026-09-29

CVE-2026-103056: Critical Command Injection in AiSOC Reaches Managed Endpoints via CrowdStrike RTR

"A critical command injection flaw in AiSOC versions 7.2.0 before 12.0.0 lets authenticated users run arbitrary commands with SYSTEM or root privileges on endpoints managed through CrowdStrike Real Time Response."

A critical command injection flaw in AiSOC versions 7.2.0 before 12.0.0 lets authenticated users run arbitrary commands with SYSTEM or root privileges on endpoints managed through CrowdStrike Real Time Response.

What Is It

CVE-2026-103056 is a command injection vulnerability (CWE-78) in the AiSOC actions service. The service builds CrowdStrike Real Time Response (RTR) command strings by inserting action parameters without escaping them. The affected code is in crowdstrike_rtr.py and endpoint.py.

An authenticated user can put single quotes into the file_path, path, script_name, or script_args parameters. This breaks out of the quoted arguments and injects extra commands. Those commands run with SYSTEM or root privileges on the targeted managed endpoints, not just on the AiSOC host.

VulnCheck disclosed the issue, and NVD has published a record for it. The NVD record is in "Received" status.

Why It Matters

Exploitation status: CVE-2026-103056 does not appear in the CISA Known Exploited Vulnerabilities catalog, so KEV does not confirm active exploitation. The sources cited here don't mention any public exploit.

What's Vulnerable

NVD doesn't list any CPEs for this CVE.

Patch Status

The affected range ends at 12.0.0, and the project has published a v12.0.0 release and a fix commit (dac3972). Organizations running AiSOC 7.2.0 through any release before 12.0.0 should upgrade to 12.0.0 or later. Until they do, they should review which users can trigger CrowdStrike RTR actions. Because the CISA KEV catalog does not list this CVE, there is no CISA-mandated required action or due date.

Sources