Junglewise Threat Intelligence

CVE-2026-8665: Rapid7 InsightConnect Translate Plugin OS command injection in TR action

CVE-2026-8665 · Severity: high · CVSS 7.7 · Published 2026-06-25

Vendors: Rapid7.

Executive brief

A security vulnerability exists in the Rapid7 InsightConnect Translate plugin, which is used to automate text transformations within security workflows. An attacker can exploit this flaw to run unauthorized commands on the underlying Linux system by providing specially crafted text inputs. This could lead to a full system takeover, data theft, or disruption of automated security operations.

Technical details

An OS command injection vulnerability (CWE-78) exists in the TR action of the Rapid7 InsightConnect Translate Plugin on Linux. The root cause is insufficient input sanitization of the 'text' or 'expression' parameters during the construction of shell commands. A remote attacker can exploit this by submitting malicious strings that break out of the intended command context to execute arbitrary OS commands. While the attack vector is network-based and requires no privileges, the CVSS assessment indicates high complexity (AC:H). The vulnerability is addressed in version 2.0.3 of the plugin.

Affected products

  • Rapid7 InsightConnect Translate Plugin (TR) < 2.0.3

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory
  • 2026-06-24: patched: Fixed in version 2.0.3

References