Uncontrolled Search Path Vulnerability in Rapid7 InsightVM on Windows
CVE-2026-89325

7.8HIGH

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
24 September 2026

What is CVE-2026-89325?

A local, low-privileged user can exploit an uncontrolled search path element vulnerability in the Rapid7 Insight Agent running on Windows. This flaw allows the user to execute malicious code with SYSTEM privileges when the assessment content of InsightVM at or below version 0.0.261.0 generates a command using the PATH environment variable. If the PATH includes a user-writable directory that precedes legitimate software installations, the adversary can drop a malicious executable named 'code' into that directory and induce the system to execute it. This vulnerability has been patched in assessment content version 0.0.269.0, released on September 15, 2026, with automatic updates deployed to affected users.

Affected Version(s)

Insight Agent Windows 0 <= 0.0.261.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.