CVE-2024-11401: RAPID7 Insight Platform

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Rapid7 Insight Platform versions prior to November 13th 2024, suffer from a privilege escalation vulnerability whereby, due to a lack of authorization checks, an attacker can successfully update the password policy in the platform settings as a standard user by crafting an API (the functionality was not possible through the platform's User Interface). This vulnerability has been fixed as of November 13th 2024.

Affected products

Published 2024-12-11. Last modified 2026-06-17.