CVE-2026-8659
EUVD-2026-3915225.06.2026, 00:17
OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters during connection configuration due to insufficient input validation.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| rapid7 | insightconnect_sqlmap | 𝑥 < 2.0.1 |
𝑥
= Vulnerable software versions