Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6482

26
FAUCET Score

CVE-2026-6482 is a local privilege escalation vulnerability affecting Rapid7 Insight Agent versions greater than 4.1.0.2 on Windows systems. The flaw stems from the agent service attempting to load an OpenSSL configuration file from a writable directory during startup, allowing unprivileged users to plant malicious configuration files and achieve SYSTEM-level code execution. The vulnerability presents a low-complexity attack vector requiring local access, with the potential for complete host compromise. An unauthenticated standard user can exploit this weakness to bypass security controls and gain full administrative access to the affected Windows host through the high-privilege agent service. Exploitation status remains minimal at present. The vulnerability is not listed in the Known Exploited Vulnerabilities catalog, has not been added to any active hot lists, and demonstrates extremely low real-world exploitation activity with an EPSS score of 0.000060000. However, organizations running vulnerable versions should prioritize patching to mitigate the risk of future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 4.1.0.2CPE match
cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:*
< 4.1.0.2CPE matchmatch criteria
cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.5HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
LOW
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
LOW
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 6th percentile among its peer group of 11,616 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

docs.rapid7.com / insight/release-notes-2026-april
Release Notes