Junglewise Threat Intelligence

CVE-2026-14172: Rapid7 InsightVM and Insight Agent privilege escalation via unvalidated file execution

CVE-2026-14172 · Severity: high · CVSS 7.8 · Published 2026-07-24

Technologies: Rapid7 Insight Agent. Vendors: Rapid7.

Executive brief

Rapid7 vulnerability management tools and agents contain a flaw that allows a local user with low privileges to execute unauthorized code. This occurs because the software runs discovered files during security scans without checking who owns them. An attacker could use this to gain full control over a system (root or SYSTEM privileges) or hijack the credentials used for security scanning.

Technical details

A privilege escalation vulnerability exists in Rapid7 InsightVM, Nexpose, and the Insight Agent due to improper validation of file ownership (CWE-250). During authenticated assessments, the Scan Engine and Insight Agent may execute discovered binaries found on the target system. Because the software does not verify that these files are owned by a trusted user, a local attacker with low privileges can place a malicious executable in a location where it will be discovered and run. This allows the attacker to execute code with the privileges of the scan credential (for Scan Engine) or as root/SYSTEM (for Insight Agent). The issue is resolved in Scan Engine content version 1.1.3935 and Insight Agent content component 0.0.245.0.

Affected products

  • Rapid7 InsightVM Scan Engine content < 1.1.3935
  • Rapid7 Nexpose Scan Engine content < 1.1.3935
  • Rapid7 Insight Agent Content component < 0.0.245.0

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References

Related threats