CVE 7.7 HIGH

OS Command Injection in Rapid7 InsightConnect Ping Plugin_CVE-2026-8660

7.7 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Description

OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter due to insufficient input validation when constructing shell commands.

Basic Information

ID CVE-2026-8660
Source rapid7
Published Jun 25, 2026 at 00:52

Affected Product

Vendor Rapid7
Product InsightConnect Ping Plugin
Affected Versions Rapid7 InsightConnect Ping Plugin 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.