CVE-2026-4837 is an eval() injection vulnerability in the Rapid7 Insight Agent affecting Linux versions. The flaw exists in the agent's beaconing logic and could theoretically enable remote code execution with root privileges through a specially crafted beacon response. However, exploitation is significantly constrained by the agent's implementation of mutual TLS (mTLS) authentication, which validates commands from the Rapid7 Platform and effectively prevents remote exploitation without prior compromise of the backend infrastructure. The vulnerability carries a CVSS 3.1 score of 6.6 (Medium) with a network attack vector but high attack complexity and high privilege requirements. While the potential impact is severe—affecting confidentiality, integrity, and availability—the practical risk is substantially mitigated by the mTLS control mechanism. The EPSS score of 0.003 indicates minimal probability of exploitation in the wild, positioning this vulnerability below the 99.5th percentile for exploitability among all CVEs. There is no evidence of active exploitation. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, no public exploit code appears to be available, and community attention remains minimal. The "Inactive" status on the Hot List further confirms this is not a priority threat requiring immediate action for most organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1.0.2CPE matchmatch criteria | cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:* | ||
>= 0, < 4.1.0.2CPE match | cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.