« Back to list

Rapid7

Rapid7 Insightvm: vulnerabilities and CVEs

Rapid7 Insightvm has 11 published vulnerabilities, 3 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs11
Last 12 months3
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-89325High (7.8)0.13%—Sep 24, 2026
An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the…
CVE-2026-14172High (7.8)0.16%—Jul 24, 2026
Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential…
CVE-2026-1568Critical (9.6)0.15%—Feb 3, 2026
Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup…
CVE-2024-6504Medium (5.3)0.32%—Jul 18, 2024
Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM Console can cause it to overload or crash by sending repeated invalid…
CVE-2024-2745Low (3.3)0.18%—Apr 2, 2024
Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the…
CVE-2021-3844Medium (5.4)0.36%—Mar 24, 2023
Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user. For example, if a user's password is changed by an administrator due…
CVE-2023-0681Medium (6.1)0.33%—Mar 20, 2023
Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the…
CVE-2017-5242High (7.7)0.38%—Jan 12, 2023
Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated the first time a virtual appliance boots.
CVE-2022-4261Medium (6.5)0.31%—Dec 8, 2022
Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of…
CVE-2019-5641Medium (5.3)0.38%—Sep 21, 2022
Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the…
CVE-2019-5615Medium (6.5)0.79%—Apr 9, 2019
Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Global Administrators and clear-text passwords for restoring backups, as well as the salt for those…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation1
  2. T1574.007 Path Interception by PATH Environment Variable1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Rapid7