Skip to content
Threat Feed
high advisory

Command Injection Vulnerability in AiSOC Actions Service

AiSOC versions 7.2.0 through 11.9.9 are vulnerable to authenticated command injection via unescaped parameters in the actions service, allowing arbitrary command execution with elevated privileges.

CVE search metadata

CVE search record: CVE-2026-103056. Severity: critical. CVSS: 9.0. KEV: no. Product: AiSOC (7.2.0 - 11.9.9), AiSOC (< 12.0.0), AiSOC (7.5.0-11.9.9). Brief: Command Injection Vulnerability in AiSOC Actions Service. Brief link: https://feed.craftedsignal.io/briefs/2026-09-aisoc-cmd-injection/

What's new

  • 1. added coverage for AiSOC (7.5.0-11.9.9) Sep 30, 02:31 via nvd
  • 2. added coverage for AiSOC (< 12.0.0) Sep 30, 02:31 via nvd

AiSOC versions 7.2.0 through 11.9.9 contain a critical command injection vulnerability within the actions service. The flaw originates from the insecure handling of action parameters in the crowdstrike_rtr.py and endpoint.py modules, where inputs such as file_path, path, script_name, or script_args are interpolated into system command strings without proper escaping. Authenticated users can provide specially crafted input containing single quotes to break out of shell argument quoting. This enables the execution of arbitrary commands with the privileges of the AiSOC service, which typically operates as SYSTEM on Windows or root on Linux/macOS. This vulnerability is particularly severe because it allows an authenticated user to gain full control over managed endpoints, potentially leading to unauthorized data access, persistence, or lateral movement within the environment.

Impact

Successful exploitation allows an authenticated attacker to achieve arbitrary code execution on any endpoint managed by the vulnerable AiSOC agent. In enterprise environments, this represents a significant risk to host integrity, as the AiSOC service is designed to run with elevated privileges to facilitate real-time response and administrative tasks. Compromise of these endpoints can be leveraged to disable security controls, exfiltrate sensitive data, or install additional malicious tools across the network.

Recommendation

  • Upgrade all instances of AiSOC to version 12.0.0 or later immediately to patch CVE-2026-103056.
  • Audit logs for the AiSOC actions service for anomalous parameter input patterns containing single quotes or shell metacharacters.
  • Restrict access to the AiSOC administrative console to authorized security personnel only to mitigate the risk of authenticated exploitation.
  • Implement strict input validation and command parameterization for all service-based task execution modules.

Immediate actions

Upgrade AiSOC to version 12.0.0 or later

IT Operations 24h

Mitigations

Upgrade AiSOC to version 12.0.0

immediate IT Operations

CVE-2026-103056