<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>AiSOC - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/aisoc/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 02:30:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/aisoc/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Command Injection Vulnerability in AiSOC Actions Service</title><link>https://feed.craftedsignal.io/briefs/2026-09-aisoc-cmd-injection/</link><pubDate>Wed, 30 Sep 2026 02:30:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-aisoc-cmd-injection/</guid><description>AiSOC versions 7.2.0 through 11.9.9 are vulnerable to authenticated command injection via unescaped parameters in the actions service, allowing arbitrary command execution with elevated privileges.</description><content:encoded><![CDATA[<p>AiSOC versions 7.2.0 through 11.9.9 contain a critical command injection vulnerability within the actions service. The flaw originates from the insecure handling of action parameters in the <code>crowdstrike_rtr.py</code> and <code>endpoint.py</code> modules, where inputs such as <code>file_path</code>, <code>path</code>, <code>script_name</code>, or <code>script_args</code> are interpolated into system command strings without proper escaping. Authenticated users can provide specially crafted input containing single quotes to break out of shell argument quoting. This enables the execution of arbitrary commands with the privileges of the AiSOC service, which typically operates as SYSTEM on Windows or root on Linux/macOS. This vulnerability is particularly severe because it allows an authenticated user to gain full control over managed endpoints, potentially leading to unauthorized data access, persistence, or lateral movement within the environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated attacker to achieve arbitrary code execution on any endpoint managed by the vulnerable AiSOC agent. In enterprise environments, this represents a significant risk to host integrity, as the AiSOC service is designed to run with elevated privileges to facilitate real-time response and administrative tasks. Compromise of these endpoints can be leveraged to disable security controls, exfiltrate sensitive data, or install additional malicious tools across the network.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of AiSOC to version 12.0.0 or later immediately to patch CVE-2026-103056.</li>
<li>Audit logs for the AiSOC actions service for anomalous parameter input patterns containing single quotes or shell metacharacters.</li>
<li>Restrict access to the AiSOC administrative console to authorized security personnel only to mitigate the risk of authenticated exploitation.</li>
<li>Implement strict input validation and command parameterization for all service-based task execution modules.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>command-injection</category><category>rce</category><category>authentication-bypass</category><category>cloud-security</category><category>cve-2026-103055</category><category>webserver</category><category>realtime-services</category></item></channel></rss>