CVE-2026-14172
Received Received - Intake

Rapid7 InsightVM Code Execution via Unvalidated Executables

Vulnerability report for CVE-2026-14172, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: Rapid7, Inc.

Description

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
rapid7 insightvm 1.1.3935
rapid7 nexpose *
rapid7 insight_agent 0.0.245.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-250 The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Rapid7 InsightVM, Nexpose, and Insight Agent run discovered executables during authenticated scans without checking file ownership. This lets a local low-privileged user execute code as the scan credential or as root/SYSTEM on the Insight Agent.

Detection Guidance

To detect this vulnerability, check the versions of Rapid7 InsightVM, Nexpose, or Insight Agent on your systems. Compare them against the fixed versions: Scan Engine content 1.1.3935 or Insight Agent content component 0.0.245.0. Use commands like 'rpm -qa | grep insight' or 'dpkg -l | grep insight' to list installed packages.

Impact Analysis

An attacker with local access could escalate privileges to run malicious code as root or the scan service account, potentially compromising the entire system or network.

Compliance Impact

This vulnerability could lead to unauthorized code execution, violating data protection requirements under GDPR and HIPAA by enabling access to sensitive data or systems.

Mitigation Strategies

Update Scan Engine content to version 1.1.3935 or later and Insight Agent content component to 0.0.245.0 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14172. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart