CVE-2026-6482: Local Privilege Escalation via OpenSSL configuration file in Insight Agent
The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a Windows host. Upon startup the agent service attempts to load an OpenSSL configuration file from a non-existent directory that is writable by standard users. By planting a crafted openssl.cnf file an attacker can trick the high-privilege service into executing arbitrary commands. This effectively permits an unprivileged user to bypass security controls and achieve a full host compromise under the agent’s SYSTEM level access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rapid7 Insight Agentto a version that resolves this vulnerability.Fixed in > 4.1.0.2 - Compensating control
Harden the directory the Rapid7 Insight Agent service tries to load the OpenSSL configuration file from (it is a non-existent directory that is writable by standard users) so standard users cannot write there, preventing a crafted openssl.cnf from being planted for privilege escalation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6482?
CVE-2026-6482 is rated as a high severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2026-6482?
To mitigate CVE-2026-6482, update the Rapid7 Insight Agent to the latest version that is greater than 4.1.0.2.
Who is affected by CVE-2026-6482?
CVE-2026-6482 affects users of Rapid7 Insight Agent versions greater than 4.1.0.2 on Windows systems.
What type of vulnerability is CVE-2026-6482?
CVE-2026-6482 is classified as a local privilege escalation vulnerability.
When was CVE-2026-6482 disclosed?
CVE-2026-6482 was disclosed in 2026 and affects versions of the Insight Agent released prior to the fix.