Ghostwire

CVE-2026-14172: Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without...

HIGH CVSS 0.0 EPSS 0.11%

Published: July 24, 2026 | Last Modified: July 24, 2026

Description

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.11% (1th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References