CVE-2026-14172

Summary

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.

Affected Software

VendorProductVersion RangeStatus
Rapid7InsightVM0 < 1.1.3935affected
Rapid7Nexpose0 < 1.1.3935affected
Rapid7Insight Agent0 < 0.0.245.0affected

Weaknesses

  • CWE-250: CWE-250 Execution with Unnecessary Privileges

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References