Junglewise Threat Intelligence

CVE-2026-8592: Rapid7 InsightConnect AWK Plugin OS command injection in process_string

CVE-2026-8592 · Severity: high · CVSS 7.7 · Published 2026-06-25

Vendors: Rapid7.

Executive brief

Rapid7 InsightConnect is an automation platform used by security teams to streamline workflows. A vulnerability in its AWK plugin allows attackers to run unauthorized commands on the underlying Linux system. This could lead to a full system takeover, data theft, or disruption of security automation processes.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Rapid7 InsightConnect AWK Plugin for Linux. The flaw is located within the 'process_string' action, where the 'text' and 'expression' parameters are used to construct shell commands without sufficient sanitization. A remote attacker can exploit this by providing specially crafted input to execute arbitrary OS commands in the context of the plugin's processing pipeline. While the attack vector is network-based, the CVSS score reflects high complexity (AC:H), likely due to specific configuration or workflow requirements. The issue is resolved in version 1.2.2.

Affected products

  • Rapid7 InsightConnect AWK Plugin < 1.2.2

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory

References