What is CVE-2026-14172?
CVE-2026-14172 involves Rapid7 InsightVM, Nexpose, and Insight Agent executing discovered executables during authenticated scans without validating file ownership. This allows a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Updating to Scan Engine content 1.1 is recommended.
Azərbaycanca: CVE-2026-14172 zəifliyi Rapid7 InsightVM, Nexpose və Insight Agent məhsullarında autentifikasiyalı skan zamanı aşkarlanan icra olunan faylların sahiblik yoxlaması olmadan işə salınması ilə bağlıdır. Bu, yerli aşağı səlahiyyətli istifadəçiyə Scan Engine kimi (Scan kredensialı ilə) və ya Insight Agent kimi (root/SYSTEM ilə) kod icra etməyə imkan verir. Scan Engine content 1.1 versiyasına yenilənmək tövsiyə olunur.
FAQ2
Which Rapid7 products are affected by CVE-2026-14172?
CVE-2026-14172 affects Rapid7 InsightVM, Nexpose, and Insight Agent products.
What is the recommended mitigation for CVE-2026-14172?
Updating to Scan Engine content version 1.1 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.