Product
AiSOC versions 7.2.0 through 11.9.9 are vulnerable to authenticated command injection via unescaped parameters in the actions service, allowing arbitrary command execution with elevated privileges.