CVE-2026-8658: OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin
OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parameters due to insufficient input sanitization in shell command construction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8658?
The severity of CVE-2026-8658 is classified as medium with a score of 6.
How do I fix CVE-2026-8658?
To mitigate CVE-2026-8658, ensure that proper input validation and sanitization are implemented in the Rapid7 InsightConnect Tcpdump Plugin.
What exploitation methods are associated with CVE-2026-8658?
CVE-2026-8658 can be exploited through OS command injection via options or filter parameters.
Who is affected by CVE-2026-8658?
CVE-2026-8658 affects users of the Rapid7 InsightConnect Tcpdump Plugin on Linux.
What types of attacks are possible with CVE-2026-8658?
CVE-2026-8658 allows authenticated attackers to execute arbitrary OS commands due to insufficient input sanitization.