Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to Scan Engine content version 1.1.3935 or later (InsightVM and Nexpose) and Insight Agent content component version 0.0.245.0 or later. Internet-connected deployments receive these fixes automatically via content updates. Air-gapped or offline deployments should apply the corresponding content update via the offline content update process.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 24 Jul 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rapid7
Rapid7 insight Agent Rapid7 insightvm Rapid7 nexpose |
|
| Vendors & Products |
Rapid7
Rapid7 insight Agent Rapid7 insightvm Rapid7 nexpose |
Fri, 24 Jul 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0. | |
| Title | Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable Invocation | |
| Weaknesses | CWE-250 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-07-24T06:05:31.460Z
Reserved: 2026-06-30T06:49:55.764Z
Link: CVE-2026-14172
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T07:30:06Z