CVE-2026-4837

An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is unlikely that the eval() function could be exploited remotely without prior, highly privileged access to the backend platform.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:*

History

02 Jun 2026, 17:56

Type Values Removed Values Added
First Time Rapid7 insight Agent
Rapid7
CPE cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:*
References () https://docs.rapid7.com/insight/release-notes-2026-april/#improvements-and-fixes - () https://docs.rapid7.com/insight/release-notes-2026-april/#improvements-and-fixes - Release Notes

08 Apr 2026, 17:21

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 17:21

Updated : 2026-06-02 17:56


NVD link : CVE-2026-4837

Mitre link : CVE-2026-4837

CVE.ORG link : CVE-2026-4837


JSON object : View

Products Affected

rapid7

  • insight_agent
CWE
CWE-95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')