CVE-2026-89325
Awaiting Analysis Awaiting Analysis - Queue

BaseFortify

Vulnerability report for CVE-2026-89325, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: Rapid7, Inc.

Description

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Assessment content at or below version 0.0.261.0 included a check that invoked the `code` command without a fully qualified path from a process running as SYSTEM. The command was resolved against the machine PATH environment variable at execution time. Where the machine PATH contained a directory writable by non-administrative users and ordered ahead of the legitimate Visual Studio Code installation, a local user could place an executable named `code` in that directory and cause the agent to execute it with SYSTEM privileges. The version range above refers to InsightVM assessment content versions, not Insight Agent versions. All Insight Agent versions were affected while running assessment content at or below 0.0.261.0. Assessment content is delivered to all Insight Agents via the Rapid7 Insight Platform independently of the Insight Agent version and is not customer-managed. This issue was resolved in assessment content version 0.0.269.0, which was made generally available on September 15, 2026. Remediation was deployed automatically and no customer action is required.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-427 The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Rapid7 Insight Agent on Windows where a local low-privileged user can execute arbitrary code as SYSTEM. The issue occurs because the agent's assessment content calls the 'code' command without a full path, allowing it to be resolved from the system PATH. If a writable directory appears before the real Visual Studio Code installation in PATH, an attacker can place a malicious 'code' executable there to gain SYSTEM privileges.

Detection Guidance

Check the version of InsightVM assessment content running on your system. If it is at or below 0.0.261.0, the vulnerability is present. Use commands like 'insightvm-agent status' or check logs for assessment content version details.

Impact Analysis

If you use Rapid7 Insight Agent on Windows with assessment content version 0.0.261.0 or earlier, a local attacker with low privileges could exploit this to run malicious code on your system with SYSTEM-level permissions. This could allow them to install malware, steal data, or take full control of the affected machine.

Compliance Impact

This vulnerability could potentially impact compliance with standards like GDPR and HIPAA by allowing unauthorized code execution with SYSTEM privileges on affected systems. Local privilege escalation risks may lead to data breaches or unauthorized access, which are critical concerns under these regulations.

Mitigation Strategies

Ensure assessment content is updated to version 0.0.269.0 or later. No manual action is required as the fix was deployed automatically on September 15, 2026. Verify the update by checking the assessment content version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89325. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart