VendorsRapid7insight_agentall versions
Vulnerabilities

Rapid7 Insight Agent

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-6482
Local Privilege Escalation via OpenSSL configuration file in Insight Agent
Published 2026-04-17 · Analyzed
8.5EPSS 0.002
CVE-2019-5629
Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent 2.6.3 and prior starts, the Python interpreter attempts to load python3.dll at "C:\DLLs\python3.dll," which normally is writable by locally authenticated users. Because of this, a malicious local user could use Insight Agent's startup conditions to elevate to SYSTEM privileges. This issue was fixed in Rapid7 Insight Agent 2.6.4.
Published 2019-07-13 · Modified
7.8EPSS 0.009
CVE-2022-0237
Rapid7 Insight Agent Privilege Escalation
Published 2022-03-17 · Modified
7.8EPSS 0.005
CVE-2021-4007
Rapid7 Insight Agent Privilege Escalation
Published 2021-12-14 · Modified
7.8EPSS 0.003
CVE-2023-2273
Rapid7 Insight Agent Directory Traversal
Published 2023-04-26 · Modified
7.5EPSS 0.007
CVE-2026-4837
Eval Injection in Rapid7 Insight Agent
Published 2026-04-08 · Analyzed
7.2EPSS 0.007
CVE-2026-4482
Insight Agent Private Key Information Disclosure via Inherited File Permissions
Published 2026-04-10 · Analyzed
6.8EPSS 0.001
CVE-2021-4016
Rapid7 Insight Agent Improper Access Control
Published 2022-01-21 · Modified
4.0EPSS 0.002