Junglewise Threat Intelligence

CVE-2026-8660: Rapid7 InsightConnect Ping Plugin OS command injection in ping action

CVE-2026-8660 · Severity: high · CVSS 7.7 · Published 2026-06-25

Vendors: Rapid7.

Executive brief

Rapid7 InsightConnect Ping Plugin is a tool used within automation workflows to check the connectivity of network devices. A security flaw allows an attacker to inject and run their own commands on the underlying Linux system by providing a specially crafted hostname. This could lead to a full system takeover, unauthorized data access, or disruption of automated security operations.

Technical details

An OS command injection vulnerability (CWE-78) exists in the 'ping' action of the Rapid7 InsightConnect Ping Plugin for Linux. The flaw is located in the handling of the 'host' parameter, where the application fails to properly sanitize input before using it to construct a shell command. A remote attacker can exploit this by supplying malicious characters or commands within the host field. Successful exploitation allows for arbitrary code execution with the privileges of the plugin process. The vulnerability is addressed in version 1.0.4.

Affected products

  • Rapid7 InsightConnect Ping Plugin < 1.0.4

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory
  • 2026-06-24: patched: Fixed in version 1.0.4

References