Junglewise Threat Intelligence

CVE-2026-9155: Rapid7 InsightConnect Sed Plugin OS command injection

CVE-2026-9155 · Severity: high · CVSS 8.8 · Published 2026-06-25

Technologies: Rapid7 InsightConnect Sed Plugin. Vendors: Rapid7.

Executive brief

A security vulnerability exists in the Rapid7 InsightConnect Sed plugin, a tool used for automated text manipulation within security workflows. An authorized user can exploit this flaw to run unauthorized commands on the underlying Linux server. This could lead to a complete system takeover, data theft, or disruption of automated security operations.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Rapid7 InsightConnect Sed Plugin for Linux. The flaw is located in the handling of the 'expression' parameter, which lacks sufficient input validation before being passed to a system shell. An authenticated attacker with network access to the plugin can inject malicious shell commands to be executed with the privileges of the plugin process. This can result in full system compromise, unauthorized data access, and lateral movement. The issue is resolved in version 2.0.5.

Affected products

  • Rapid7 InsightConnect Sed Plugin < 2.0.5

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats