CVE-2026-4837
Last modified
CVE-2026-4837 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is unlikely that the eval() function could be exploited remotely without prior, highly privileged access to the backend platform.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is unlikely that the eval() function could be exploited remotely without prior, highly privileged access to the backend platform.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rapid7 | Insight Agent | < 4.1.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-4837?
How severe is CVE-2026-4837?
How do I fix CVE-2026-4837?
Are you affected by CVE-2026-4837?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
