CVE 7.7 HIGH

OS Command Injection in Rapid7 InsightConnect AWK Plugin_CVE-2026-8592

7.7 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Description

OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processing pipeline.

Basic Information

ID CVE-2026-8592
Source rapid7
Published Jun 25, 2026 at 01:32

Affected Product

Vendor Rapid7
Product InsightConnect AWK Plugin
Affected Versions Rapid7 InsightConnect AWK Plugin 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.