CVE-2026-8662

Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is limited to file corruption as content cannot be controlled by the attacker.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:rapid7:insightconnect_compression:*:*:*:*:*:rapid7:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

29 Jun 2026, 19:22

Type Values Removed Values Added
First Time Linux
Rapid7 insightconnect Compression
Linux linux Kernel
Rapid7
CPE cpe:2.3:a:rapid7:insightconnect_compression:*:*:*:*:*:rapid7:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
References () https://extensions.rapid7.com/extension/compression - () https://extensions.rapid7.com/extension/compression - Product

25 Jun 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-25 03:16

Updated : 2026-06-29 19:22


NVD link : CVE-2026-8662

Mitre link : CVE-2026-8662

CVE.ORG link : CVE-2026-8662


JSON object : View

Products Affected

linux

  • linux_kernel

rapid7

  • insightconnect_compression
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')