Junglewise Threat Intelligence

CVE-2026-4837: Rapid7 Insight Agent eval injection in Linux beaconing logic

CVE-2026-4837 · Severity: medium · CVSS 6.6 · Published 2026-04-08

Technologies: Rapid7 Insight Agent. Vendors: Rapid7.

Executive brief

A security vulnerability exists in the Rapid7 Insight Agent for Linux, a software component used for endpoint monitoring and security data collection. Under specific conditions, an attacker who has already compromised the central management platform could execute malicious commands on individual Linux systems with full administrative (root) privileges. While the impact is severe, the risk is mitigated by the fact that an attacker would first need highly privileged access to Rapid7's backend infrastructure to bypass security checks.

Technical details

An eval() injection vulnerability (CWE-95) exists in the beaconing logic of the Rapid7 Insight Agent for Linux. The flaw resides in how the agent processes responses from the Rapid7 Platform, where improperly neutralized directives in dynamically evaluated code can lead to remote code execution (RCE) as the root user. Exploitation is considered difficult (AC:H) because the agent utilizes mutual TLS (mTLS) to verify commands. An attacker would require prior, highly privileged access to the Rapid7 backend platform to send a malicious beacon response that the agent would trust. The issue is resolved in Insight Agent version 4.1.0.2.

Affected products

  • Rapid7 Insight Agent versions prior to 4.1.0.2

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-27: patched: Fix included in April 2026 release notes for Insight Agent 4.1.0.2

References

Related threats