CVE-2026-14172 PUBLISHED

Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable Invocation

Assigner: rapid7
Reserved: 30.06.2026 Published: 24.07.2026 Updated: 24.07.2026

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.8

Product Status

Vendor Rapid7
Product InsightVM
Versions Default: unaffected
  • affected from 0 to 1.1.3935 (excl.)
Vendor Rapid7
Product Nexpose
Versions Default: unaffected
  • affected from 0 to 1.1.3935 (excl.)
Vendor Rapid7
Product Insight Agent
Versions Default: unaffected
  • affected from 0 to 0.0.245.0 (excl.)

Solutions

Update to Scan Engine content version 1.1.3935 or later (InsightVM and Nexpose) and Insight Agent content component version 0.0.245.0 or later. Internet-connected deployments receive these fixes automatically via content updates. Air-gapped or offline deployments should apply the corresponding content update via the offline content update process.

Credits

  • Paul Miseiko of Rapid7 finder
  • Patrick Fitzsimons of Rapid7 finder

References

Problem Types

  • CWE-250 Execution with Unnecessary Privileges CWE

Impacts

  • An unprivileged local user can achieve arbitrary code execution as root (Linux/macOS) or SYSTEM (Windows) via the Insight Agent, or as the configured scan credential identity via the Scan Engine, by planting a malicious executable in a user-writable directory that is then discovered and executed during assessment data collection.