CVE-2026-6482 is a local privilege escalation vulnerability affecting Rapid7 Insight Agent versions greater than 4.1.0.2 on Windows systems. The flaw stems from the agent service attempting to load an OpenSSL configuration file from a writable directory during startup, allowing unprivileged users to plant malicious configuration files and achieve SYSTEM-level code execution. The vulnerability presents a low-complexity attack vector requiring local access, with the potential for complete host compromise. An unauthenticated standard user can exploit this weakness to bypass security controls and gain full administrative access to the affected Windows host through the high-privilege agent service. Exploitation status remains minimal at present. The vulnerability is not listed in the Known Exploited Vulnerabilities catalog, has not been added to any active hot lists, and demonstrates extremely low real-world exploitation activity with an EPSS score of 0.000060000. However, organizations running vulnerable versions should prioritize patching to mitigate the risk of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 4.1.0.2CPE match | cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:* | ||
< 4.1.0.2CPE matchmatch criteria | cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.