CVE-2026-14172: RAPID7 Insight Agent

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.

Affected products

  • RAPID7 Insight Agent: before 0.0.245.0 (fixed in 0.0.245.0)
  • RAPID7 Insightvm: before 1.1.3935 (fixed in 1.1.3935)
  • RAPID7 Nexpose: before 1.1.3935 (fixed in 1.1.3935)

Published 2026-07-24. Last modified 2026-07-30.