Executive brief
The Rapid7 InsightConnect Finger plugin, used for automating user information lookups on Linux systems, contains a security flaw that allows authorized users to run unauthorized commands. An attacker with administrative credentials could exploit this to gain deeper access to the underlying server, potentially leading to data modification or service disruption. Organizations should update the plugin to version 1.0.3 or later to resolve this issue.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Rapid7 InsightConnect Finger Plugin on Linux. The flaw is rooted in insufficient input validation of the 'user' and 'host' parameters during the construction of shell commands. An authenticated attacker with high privileges (PR:H) can exploit this over the network to execute arbitrary OS commands on the host system. The vulnerability is addressed in version 1.0.3 of the plugin.
Affected products
- Rapid7 InsightConnect Finger Plugin < 1.0.3
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory