Skip to main content

Vendor/product archive

rapid7 / insight_agent CVEs

Beta · best-effort

8 CVEs tagged to rapid7 / insight_agent0 Critical, 3 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-6482

Published Apr 17, 2026

The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a Windows host. Upon startup t…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-4482

Published Apr 10, 2026

The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the cl…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-4837

Published Apr 8, 2026

An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via…

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2273

Published Apr 26, 2023

Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI argument flows into io.ioutil.Wri…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0237

Published Mar 17, 2022

Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argume…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-4016

Published Jan 21, 2022

Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user has access to the snapshot directory. An attacker can access,…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-4007

Published Dec 14, 2021

Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent versions 3.0.1…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5629

Published Jul 13, 2019

Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent 2.6.3 and prior s…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1