CVE-2026-8659: RAPID7 Insightconnect Sqlmap

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters during connection configuration due to insufficient input validation.

Affected products

  • RAPID7 Insightconnect Sqlmap: before 2.0.1 (fixed in 2.0.1)

Published 2026-06-25. Last modified 2026-06-29.