CVE-2026-14172
Rapid7 InsightVM, Nexpose, Insight Agent
Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.
- CVSS
- 7.8
- EPSS
- 0.11% 1.30% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.24