{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/realtime-services/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:aisoc:aisoc:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9,"id":"CVE-2026-103056"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AiSOC (7.2.0 - 11.9.9)","AiSOC (\u003c 12.0.0)","AiSOC (7.5.0-11.9.9)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","command-injection","rce","authentication-bypass","cloud-security","cve-2026-103055","webserver","realtime-services"],"_cs_type":"advisory","_cs_vendors":["AiSOC"],"content_html":"\u003cp\u003eAiSOC versions 7.2.0 through 11.9.9 contain a critical command injection vulnerability within the actions service. The flaw originates from the insecure handling of action parameters in the \u003ccode\u003ecrowdstrike_rtr.py\u003c/code\u003e and \u003ccode\u003eendpoint.py\u003c/code\u003e modules, where inputs such as \u003ccode\u003efile_path\u003c/code\u003e, \u003ccode\u003epath\u003c/code\u003e, \u003ccode\u003escript_name\u003c/code\u003e, or \u003ccode\u003escript_args\u003c/code\u003e are interpolated into system command strings without proper escaping. Authenticated users can provide specially crafted input containing single quotes to break out of shell argument quoting. This enables the execution of arbitrary commands with the privileges of the AiSOC service, which typically operates as SYSTEM on Windows or root on Linux/macOS. This vulnerability is particularly severe because it allows an authenticated user to gain full control over managed endpoints, potentially leading to unauthorized data access, persistence, or lateral movement within the environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to achieve arbitrary code execution on any endpoint managed by the vulnerable AiSOC agent. In enterprise environments, this represents a significant risk to host integrity, as the AiSOC service is designed to run with elevated privileges to facilitate real-time response and administrative tasks. Compromise of these endpoints can be leveraged to disable security controls, exfiltrate sensitive data, or install additional malicious tools across the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of AiSOC to version 12.0.0 or later immediately to patch CVE-2026-103056.\u003c/li\u003e\n\u003cli\u003eAudit logs for the AiSOC actions service for anomalous parameter input patterns containing single quotes or shell metacharacters.\u003c/li\u003e\n\u003cli\u003eRestrict access to the AiSOC administrative console to authorized security personnel only to mitigate the risk of authenticated exploitation.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and command parameterization for all service-based task execution modules.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T02:31:07Z","date_published":"2026-09-30T02:30:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-aisoc-cmd-injection/","summary":"AiSOC versions 7.2.0 through 11.9.9 are vulnerable to authenticated command injection via unescaped parameters in the actions service, allowing arbitrary command execution with elevated privileges.","title":"Command Injection Vulnerability in AiSOC Actions Service","url":"https://feed.craftedsignal.io/briefs/2026-09-aisoc-cmd-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Realtime-Services","version":"https://jsonfeed.org/version/1.1"}