Uncontrolled Search Path Vulnerability in Rapid7 InsightVM on Windows
CVE-2026-89325
7.8HIGH
What is CVE-2026-89325?
A local, low-privileged user can exploit an uncontrolled search path element vulnerability in the Rapid7 Insight Agent running on Windows. This flaw allows the user to execute malicious code with SYSTEM privileges when the assessment content of InsightVM at or below version 0.0.261.0 generates a command using the PATH environment variable. If the PATH includes a user-writable directory that precedes legitimate software installations, the adversary can drop a malicious executable named 'code' into that directory and induce the system to execute it. This vulnerability has been patched in assessment content version 0.0.269.0, released on September 15, 2026, with automatic updates deployed to affected users.
Affected Version(s)
Insight Agent Windows 0 <= 0.0.261.0
