CVE-2026-14172
Rapid7 InsightVM, Nexpose, Insight Agent 취약점
Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.
- 대응 우선순위
- 점검
- CVSS
- 7.8
- EPSS
- 0.11% 백분위 1.30% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.24