Rapid7 · Insightvm · CVE-2026-14172
**Name of the Vulnerable Software and Affected Versions**
Rapid7 InsightVM (affected versions not specified)
Nexpose (affected versions not specified)
Rapid7 Insight Agent versions prior to 0.0.245.0
Rapid7 Scan Engine versions prior to 1.1.3935
**Description**
Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership. This allows a local low-privileged user to execute arbitrary code with the privileges of the scan credential when using the Scan Engine, or as root/SYSTEM when using the Insight Agent.
**Recommendations**
Update Rapid7 Insight Agent to version 0.0.245.0 or later.
Update Rapid7 Scan Engine to version 1.1.3935 or later.