Crowdstrike · Crowdstrike Real Time Response · CVE-2026-103056
**Name of the Vulnerable Software and Affected Versions**
AiSOC versions 7.2.0 through 11.x
**Description**
The actions service contains a flaw when building CrowdStrike Real Time Response command strings by interpolating unescaped action parameters within `crowdstrike rtr.py` and `endpoint.py`. Authenticated users can inject single quotes into the `file path`, `path`, `script name`, or `script args` parameters to bypass quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.
**Recommendations**
Update AiSOC to version 12.0.0 or later.
Restrict the use of the `file path`, `path`, `script name`, and `script args` parameters until the update is applied.