CVE-2026-14172
EUVD-2026-4848724.07.2026, 07:16
Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| rapid7 | insightvm | 𝑥 < 1.1.3935 | CNA |
| rapid7 | insightvm | 𝑥 < 0.0.245.0 | CNA |
Common Weakness Enumeration