CVE-2026-103056EPSS p72.7%
CVE-2026-103056CVE-2026-103056
Description
AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.
Scoring
| CVSS | 9.0 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
| EPSS | 1.46% probability of exploitation · percentile 72.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |