
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-14172 is a local privilege escalation vulnerability affecting Rapid7 InsightVM, Nexpose, and the Insight Agent, in which discovered executables are executed during authenticated vulnerability assessments without validating file ownership. This allows a local low-privileged user to run arbitrary code as the Scan Engine service account credential, or as root/SYSTEM when exploited via the Insight Agent. The vulnerability was published on July 24, 2026, and patches were made available the same day. It carries a CVSS v3.1 base score of 7.8 (High) (Github Advisory, Rapid7 Release Notes).
The root cause is classified as CWE-250 (Execution with Unnecessary Privileges): during authenticated vulnerability assessments, the Scan Engine and Insight Agent discover and execute files on the target system without verifying that those files are owned by a trusted or expected user. A local low-privileged attacker can place a malicious executable in a directory that will be scanned, and the assessment process will execute it under the elevated context of the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). The attack vector is local, requires low privileges, no user interaction, and has low attack complexity, making it straightforward to exploit once local access is obtained. No public proof-of-concept code has been identified at this time (Github Advisory, Rapid7 Release Notes).
Successful exploitation grants a local low-privileged attacker the ability to execute arbitrary code with the privileges of the Scan Engine service account or as root/SYSTEM on systems running the Insight Agent, resulting in high confidentiality, integrity, and availability impact. This could allow an attacker to access sensitive scan data, modify system configurations, install persistent backdoors, or use the compromised high-privilege context as a stepping stone for lateral movement within the environment. The scope of impact is limited to the local system, but the elevation to root/SYSTEM represents a full host compromise (Github Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.107% (1st percentile), indicating a low near-term probability of exploitation. Exploitation requires local access to the target system, which limits the attack surface compared to remotely exploitable vulnerabilities (Github Advisory).
cmd.exe, powershell.exe, /bin/bash, or python) running under the scan service account or root/SYSTEM context.Rapid7 has released fixes in Scan Engine content version 1.1.3935 and Insight Agent content component version 0.0.245.0; organizations should update to these versions immediately. As a compensating control, restrict file write permissions in directories that are enumerated during authenticated scans to prevent low-privileged users from placing executables in those paths. Additionally, limit local system access to trusted administrators only to reduce the risk of exploitation (Rapid7 Release Notes, Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."