CVE-2026-8659: RAPID7 Insightconnect Sqlmap
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters during connection configuration due to insufficient input validation.
Affected products
- RAPID7 Insightconnect Sqlmap: before 2.0.1 (fixed in 2.0.1)
Published 2026-06-25. Last modified 2026-06-29.