Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4837

29
FAUCET Score

CVE-2026-4837 is an eval() injection vulnerability in the Rapid7 Insight Agent affecting Linux versions. The flaw exists in the agent's beaconing logic and could theoretically enable remote code execution with root privileges through a specially crafted beacon response. However, exploitation is significantly constrained by the agent's implementation of mutual TLS (mTLS) authentication, which validates commands from the Rapid7 Platform and effectively prevents remote exploitation without prior compromise of the backend infrastructure. The vulnerability carries a CVSS 3.1 score of 6.6 (Medium) with a network attack vector but high attack complexity and high privilege requirements. While the potential impact is severe—affecting confidentiality, integrity, and availability—the practical risk is substantially mitigated by the mTLS control mechanism. The EPSS score of 0.003 indicates minimal probability of exploitation in the wild, positioning this vulnerability below the 99.5th percentile for exploitability among all CVEs. There is no evidence of active exploitation. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, no public exploit code appears to be available, and community attention remains minimal. The "Inactive" status on the Hot List further confirms this is not a priority threat requiring immediate action for most organizations.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.1.0.2CPE matchmatch criteria
cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:*
>= 0, < 4.1.0.2CPE match
cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.6MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.7
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
33.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0041 is in the 11th percentile among its peer group of 5,531 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

docs.rapid7.com / insight/release-notes-2026-april
Release Notes