A critical command injection flaw in AiSOC versions 7.2.0 before 12.0.0 lets authenticated users run arbitrary commands with SYSTEM or root privileges on endpoints managed through CrowdStrike Real Time Response.
What Is It
CVE-2026-103056 is a command injection vulnerability (CWE-78) in the AiSOC actions service. The service builds CrowdStrike Real Time Response (RTR) command strings by inserting action parameters without escaping them. The affected code is in crowdstrike_rtr.py and endpoint.py.
An authenticated user can put single quotes into the file_path, path, script_name, or script_args parameters. This breaks out of the quoted arguments and injects extra commands. Those commands run with SYSTEM or root privileges on the targeted managed endpoints, not just on the AiSOC host.
VulnCheck disclosed the issue, and NVD has published a record for it. The NVD record is in "Received" status.
Why It Matters
- Severity: CVSS 3.1 base score of 9.0 (CRITICAL), vector
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H. CVSS 4.0 rates it 9.4 (CRITICAL). - Changed scope: Exploitation affects systems beyond the vulnerable component. A low-privileged AiSOC user who can trigger RTR actions could potentially reach endpoints the platform manages through CrowdStrike RTR. How many endpoints are exposed likely depends on how the deployment scopes its RTR integration and who can trigger actions.
- Highest privilege: Injected commands run as SYSTEM or root, with high impact to confidentiality, integrity and availability.
- Low barrier: The attack is network-based, has low complexity and needs only low privileges. The CVSS vector does require user interaction.
Exploitation status: CVE-2026-103056 does not appear in the CISA Known Exploited Vulnerabilities catalog, so KEV does not confirm active exploitation. The sources cited here don't mention any public exploit.
What's Vulnerable
- Vendor/Product: beenuar AiSOC (https://github.com/beenuar/AiSOC)
- Affected versions: 7.2.0 up to, but not including, 12.0.0 (semver)
- Affected components: Actions service, in
services/actions/app/clients/crowdstrike_rtr.pyandservices/actions/app/executors/endpoint.py - Affected parameters:
file_path,path,script_name,script_args
NVD doesn't list any CPEs for this CVE.
Patch Status
The affected range ends at 12.0.0, and the project has published a v12.0.0 release and a fix commit (dac3972). Organizations running AiSOC 7.2.0 through any release before 12.0.0 should upgrade to 12.0.0 or later. Until they do, they should review which users can trigger CrowdStrike RTR actions. Because the CISA KEV catalog does not list this CVE, there is no CISA-mandated required action or due date.