Junglewise Threat Intelligence

CVE-2026-9154: Rapid7 InsightConnect Sed Plugin arbitrary file write in expression parameter

CVE-2026-9154 · Severity: high · CVSS 7.1 · Published 2026-06-25

Technologies: Rapid7 InsightConnect Sed Plugin. Vendors: Rapid7.

Executive brief

A security vulnerability in the Rapid7 InsightConnect Sed Plugin for Linux allows authorized users to write data to any file on the underlying system. InsightConnect is an automation platform used for security operations, and this flaw could allow a user to corrupt system files or modify critical configurations. This could lead to service disruptions or unauthorized changes to the security environment.

Technical details

An arbitrary file write vulnerability exists in the Rapid7 InsightConnect Sed Plugin on Linux due to improper limitation of a pathname to a restricted directory (CWE-22). Authenticated attackers can exploit this by providing a specially crafted string to the 'expression' parameter, allowing them to write attacker-controlled content to arbitrary file paths on the host system. The vulnerability is reachable over the network with low privileges and requires no user interaction. A fix is available in version 2.0.5 of the plugin.

Affected products

  • Rapid7 InsightConnect Sed Plugin < 2.0.5

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats