PT-2026-64243 · Rapid7 · Insightvm+3

·

CVE-2026-14172

·

Published

2026-07-24

·

Updated

2026-07-25

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rapid7 InsightVM (affected versions not specified) Nexpose (affected versions not specified) Rapid7 Insight Agent versions prior to 0.0.245.0 Rapid7 Scan Engine versions prior to 1.1.3935
Description Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership. This allows a local low-privileged user to execute arbitrary code with the privileges of the scan credential when using the Scan Engine, or as root/SYSTEM when using the Insight Agent.
Recommendations Update Rapid7 Insight Agent to version 0.0.245.0 or later. Update Rapid7 Scan Engine to version 1.1.3935 or later.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14172

Affected Products

Insight Agent
Insightvm
Nexpose
Scan Engine