CVE-2026-14172
Nexpose vulnerability analysis and mitigation

Overview

CVE-2026-14172 is a local privilege escalation vulnerability affecting Rapid7 InsightVM, Nexpose, and the Insight Agent, in which discovered executables are executed during authenticated vulnerability assessments without validating file ownership. This allows a local low-privileged user to run arbitrary code as the Scan Engine service account credential, or as root/SYSTEM when exploited via the Insight Agent. The vulnerability was published on July 24, 2026, and patches were made available the same day. It carries a CVSS v3.1 base score of 7.8 (High) (Github Advisory, Rapid7 Release Notes).

Technical details

The root cause is classified as CWE-250 (Execution with Unnecessary Privileges): during authenticated vulnerability assessments, the Scan Engine and Insight Agent discover and execute files on the target system without verifying that those files are owned by a trusted or expected user. A local low-privileged attacker can place a malicious executable in a directory that will be scanned, and the assessment process will execute it under the elevated context of the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). The attack vector is local, requires low privileges, no user interaction, and has low attack complexity, making it straightforward to exploit once local access is obtained. No public proof-of-concept code has been identified at this time (Github Advisory, Rapid7 Release Notes).

Impact

Successful exploitation grants a local low-privileged attacker the ability to execute arbitrary code with the privileges of the Scan Engine service account or as root/SYSTEM on systems running the Insight Agent, resulting in high confidentiality, integrity, and availability impact. This could allow an attacker to access sensitive scan data, modify system configurations, install persistent backdoors, or use the compromised high-privilege context as a stepping stone for lateral movement within the environment. The scope of impact is limited to the local system, but the elevation to root/SYSTEM represents a full host compromise (Github Advisory).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.107% (1st percentile), indicating a low near-term probability of exploitation. Exploitation requires local access to the target system, which limits the attack surface compared to remotely exploitable vulnerabilities (Github Advisory).

Exploitation steps

  1. Gain Local Access: Obtain a low-privileged local user account on a system where Rapid7 InsightVM/Nexpose Scan Engine or the Insight Agent is installed and performing authenticated assessments.
  2. Identify Scan Directories: Determine which directories are enumerated and scanned for executables during authenticated vulnerability assessments (e.g., common application directories, user-writable paths).
  3. Place Malicious Executable: Write a crafted executable (e.g., a reverse shell or privilege-escalating payload) into a directory that will be discovered and executed by the scan process, taking advantage of the lack of file ownership validation.
  4. Trigger Assessment: Wait for or trigger a scheduled authenticated vulnerability assessment by the Scan Engine or Insight Agent.
  5. Achieve Privilege Escalation: The scan process executes the malicious file under the Scan Engine service account credentials or as root/SYSTEM (Insight Agent), granting the attacker elevated code execution on the host (Github Advisory).

Indicators of compromise

  • Process: Unexpected processes spawned by the Rapid7 Scan Engine or Insight Agent service (e.g., reverse shells, command interpreters such as cmd.exe, powershell.exe, /bin/bash, or python) running under the scan service account or root/SYSTEM context.
  • File System: Presence of unknown or unauthorized executables in directories commonly scanned during vulnerability assessments; newly created files owned by low-privileged users in scan-accessible paths.
  • Logs: Rapid7 Scan Engine or Insight Agent logs showing execution of unexpected binaries during assessment runs; OS audit logs (e.g., Windows Security Event Log, Linux auditd) recording process creation events under the scan service account or root for files not associated with legitimate scan activity.
  • Network: Outbound connections from the Scan Engine or Insight Agent process to unknown external IP addresses or command-and-control infrastructure, particularly following a scheduled scan.

Mitigation and workarounds

Rapid7 has released fixes in Scan Engine content version 1.1.3935 and Insight Agent content component version 0.0.245.0; organizations should update to these versions immediately. As a compensating control, restrict file write permissions in directories that are enumerated during authenticated scans to prevent low-privileged users from placing executables in those paths. Additionally, limit local system access to trusted administrators only to reduce the risk of exploitation (Rapid7 Release Notes, Github Advisory).

Additional resources


SourceThis report was generated using AI

Related Nexpose vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-1699CRITICAL9.8
  • Nexpose logoNexpose
  • cpe:2.3:a:rapid7:nexpose
NoYesMar 30, 2023
CVE-2026-14172HIGH7.8
  • Nexpose logoNexpose
  • cpe:2.3:a:rapid7:insightvm
NoYesJul 24, 2026
CVE-2022-4261MEDIUM6.5
  • Nexpose logoNexpose
  • cpe:2.3:a:rapid7:nexpose
NoYesDec 08, 2022
CVE-2022-0758MEDIUM6.1
  • Nexpose logoNexpose
  • cpe:2.3:a:rapid7:nexpose
NoYesMar 17, 2022
CVE-2022-3913MEDIUM5.3
  • Nexpose logoNexpose
  • cpe:2.3:a:rapid7:nexpose
NoYesFeb 01, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management