Executive brief
The Rapid7 InsightConnect Tcpdump plugin, used for capturing and analyzing network traffic within automation workflows, contains a security flaw. An authorized user with high-level permissions can exploit this to run unauthorized commands on the underlying Linux system. This could lead to a compromise of the automation platform, potentially allowing an attacker to modify data or disrupt security operations.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Rapid7 InsightConnect Tcpdump plugin for Linux. The flaw is located in the shell command construction logic, where the 'options' and 'filter' parameters are not properly sanitized before being executed. An authenticated attacker with high privileges (PR:H) can exploit this over the network to execute arbitrary OS commands on the host system. The issue is resolved in version 2.0.0 of the plugin.
Affected products
- Rapid7 InsightConnect Tcpdump Plugin < 2.0.0
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory