Remote Code Execution Vulnerability in Rapid7 Insight Agent for Linux
CVE-2026-4837
6.6MEDIUM
What is CVE-2026-4837?
The Rapid7 Insight Agent for Linux has an eval() injection vulnerability in its beaconing logic. An attacker with prior privileged access to the backend platform could exploit this vulnerability to achieve remote code execution as root by sending a specially crafted beacon response. Despite the inherent security measures such as mutual TLS (mTLS) for command verification, the risk of exploitation remains a concern, necessitating immediate attention and mitigation strategies for exposed systems.
Affected Version(s)
Insight Agent Linux 0 < 4.1.0.2
