CVE-2026-4482: Insight Agent Private Key Information Disclosure via Inherited File Permissions
The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4482?
CVE-2026-4482 is considered a medium severity vulnerability due to the potential exposure of sensitive private key information.
How do I fix CVE-2026-4482?
To address CVE-2026-4482, ensure that the installer certificate files in the …/bootstrap/common/ssl folder have restricted permissions to prevent unauthorized access.
Who is affected by CVE-2026-4482?
CVE-2026-4482 affects users of the Insight Agent on Windows systems where file permissions are not correctly configured.
What is the risk of CVE-2026-4482?
The primary risk of CVE-2026-4482 is the potential disclosure of private key information, which can lead to unauthorized access and data breaches.
When was CVE-2026-4482 reported?
CVE-2026-4482 was reported in April 2026 as part of improvements and fixes in Insight Agent.