PT-2026-102966 · Crowdstrike+1 · Crowdstrike Real Time Response+1

·

CVE-2026-103056

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions AiSOC versions 7.2.0 through 11.x
Description The actions service contains a flaw when building CrowdStrike Real Time Response command strings by interpolating unescaped action parameters within crowdstrike rtr.py and endpoint.py. Authenticated users can inject single quotes into the file path, path, script name, or script args parameters to bypass quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.
Recommendations Update AiSOC to version 12.0.0 or later. Restrict the use of the file path, path, script name, and script args parameters until the update is applied.

Exploit

Fix

LPE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103056
GHSA-7Q37-2WFW-XRX7

Affected Products

Aisoc
Crowdstrike Real Time Response