Insight Agent CVE Vulnerabilities
By Rapid7 — 2 known vulnerabilities
Critical
0
High
0
Medium
2
Low
0
None
0
All Insight Agent CVEs
CVE-2026-4482
5.5
medium
The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any loca
Apr 10, 2026
CVE-2026-4837
6.6
medium
An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is u
Apr 8, 2026