CVE 6 MEDIUM

OS Command Injection in Rapid7 InsightConnect Finger Plugin_CVE-2026-8664

6 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L

Description

OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host parameters due to insufficient input validation in shell command construction.

Basic Information

ID CVE-2026-8664
Source rapid7
Published Jun 25, 2026 at 01:28

Affected Product

Vendor Rapid7
Product InsightConnect Finger Plugin
Affected Versions Rapid7 InsightConnect Finger Plugin 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.