Insight Agent
Vendor:
First CVE: Jul 13, 2019 · Active for 7 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Insight Agent over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 13, 2019
7 years ago
Most Recent CVE
Apr 17, 2026
100 days ago
CVE Severity & Scoring
Insight Agent9 CVEs
11%
22%
67%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local7 (77.8%)
Network2 (22.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (77.8%)
Unknown0 (0.0%)
Required2 (22.2%)
Privileges Required
Low6 (66.7%)
High1 (11.1%)
None2 (22.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4837HIGH An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via | Apr 8, 2026 | 7.2 | 29 | NO | NO |
CVE-2026-6482HIGH The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a Windows host. Upon startup th | Apr 17, 2026 | 7.8 | 26 | NO | NO |
CVE-2019-5629HIGH Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent 2.6.3 and prior st | Jul 13, 2019 | 7.8 | 26 | NO | NO |
CVE-2022-0237HIGH Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argumen | Mar 17, 2022 | 7.8 | 25 | NO | NO |
CVE-2023-2273HIGH Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI argument flows into io.ioutil.Writ | Apr 26, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-4007HIGH Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent versions 3.0.1 t | Dec 14, 2021 | 7.8 | 24 | NO | NO |
CVE-2026-4482MEDIUM The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the cli | Apr 10, 2026 | 5.5 | 21 | NO | NO |
CVE-2024-3185MEDIUM A key used in logging.json does not follow the least privilege principle by default and is exposed to local users in the Rapid7 Platform. This allows an attacker with local acces | Apr 23, 2024 | 6.8 | 19 | NO | NO |
Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user has access to the snapshot directory. An attacker can access, | Jan 21, 2022 | 3.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Insight Agent
Top CWEs
Versions
No cataloged versions.