CVE-2026-4837: medium-severity vulnerability in Rapid7 Insight Agent
Eval Injection in Rapid7 Insight Agent
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.6epss 0.7%
exploitation probability
0.7%top 47% of all CVEs
observed exploitation
nono source reports it
An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is unlikely that the eval() function could be exploited remotely without prior, highly privileged access to the backend platform.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Rapid7 · Insight AgentRelated CVEs — Rapid7 Insight Agent
In the same product, most dangerous first.
CVE-2019-5629HIGHCVE-2019-5629EPSS 0.9%CVE-2023-2273MEDIUMRapid7 Insight Agent Directory TraversalEPSS 0.7%CVE-2022-0237MEDIUMRapid7 Insight Agent Privilege EscalationEPSS 0.5%CVE-2021-4007HIGHRapid7 Insight Agent Privilege EscalationEPSS 0.3%CVE-2021-4016MEDIUMRapid7 Insight Agent Improper Access ControlEPSS 0.2%CVE-2026-6482HIGHLocal Privilege Escalation via OpenSSL configuration file in Insight AgentEPSS 0.2%