7.8
CVE-2026-14172
- EPSS 0.11%
- Veröffentlicht 24.07.2026 05:51:14
- Zuletzt bearbeitet 30.07.2026 14:15:31
- CVE-Watchlists
- Unerledigt
Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable Invocation
Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRapid7
≫
Produkt
InsightVM
Default Statusunaffected
Version
0
Version <
1.1.3935
Status
affected
HerstellerRapid7
≫
Produkt
Nexpose
Default Statusunaffected
Version
0
Version <
1.1.3935
Status
affected
HerstellerRapid7
≫
Produkt
Insight Agent
Default Statusunaffected
Version
0
Version <
0.0.245.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.013 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Rapid7 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-250 Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
https://docs.rapid7.com/insight/release-notes-2026-july/#vulnerability-management-insightvm
https://docs.rapid7.com/insight/release-notes-2026-july/#rapid7-agent-insight-agent