CVE 6 MEDIUM

OS Command Injection in Rapid7 InsightConnect RPM Plugin_CVE-2026-8663

6 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L

Description

OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name parameters due to insufficient input sanitization in shell command construction.

Basic Information

ID CVE-2026-8663
Source rapid7
Published Jun 24, 2026 at 23:56

Affected Product

Vendor Rapid7
Product InsightConnect RPM Plugin
Affected Versions Rapid7 InsightConnect RPM Plugin 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.