Executive brief
Rapid7 InsightConnect is an automation platform used by security teams to streamline workflows. A vulnerability in its SQLmap plugin allows an authorized user to run unauthorized commands on the underlying Linux system. This could lead to a compromise of the automation server, potentially allowing an attacker to disrupt security operations or access sensitive configuration data.
Technical details
An OS Command Injection vulnerability (CWE-78) exists in the Rapid7 InsightConnect SQLmap Plugin for Linux. The flaw is located within the connection configuration logic, specifically failing to properly sanitize the 'api_host' and 'api_port' parameters. An authenticated attacker with high privileges can exploit this over the network to execute arbitrary shell commands on the host system. The issue is resolved in version 2.0.1 of the plugin.
Affected products
- Rapid7 InsightConnect SQLmap Plugin < 2.0.1
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory