The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 10 Apr 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user. | |
| Title | Insight Agent Private Key Information Disclosure via Inherited File Permissions | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-04-10T04:22:38.719Z
Reserved: 2026-03-20T05:21:38.041Z
Link: CVE-2026-4482
No data.
Status : Received
Published: 2026-04-10T05:16:04.587
Modified: 2026-04-10T05:16:04.587
Link: CVE-2026-4482
No data.
OpenCVE Enrichment
No data.
Weaknesses