CVE-2026-8659: OS Command Injection in Rapid7 InsightConnect SQLmap Plugin
Published Jun 25, 2026
·Updated
OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the apihost or apiport parameters during connection configuration due to insufficient input validation.
Affected Software
3 affected components
Rapid7 InsightConnect SQLmap Plugin
All of the following
Rapid7 Insightconnect Sqlmap Rapid7<2.0.1
Linux Linux kernel
Event History
Jun 25, 2026
CVE Published
via MITRE·12:07 AM
Data Sourced
via MITRE·12:07 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 AM
DescriptionSeverityWeaknessAffected Software
Jul 25, 58465
Event
via FIRST·04:35 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-8659?
The severity of CVE-2026-8659 is medium with a score of 6.
2
How do I fix CVE-2026-8659?
To fix CVE-2026-8659, ensure that input validation is implemented properly for the api_host and api_port parameters in the Rapid7 InsightConnect SQLmap Plugin.
3
What type of vulnerability is CVE-2026-8659?
CVE-2026-8659 is classified as an OS Command Injection vulnerability.
4
Who is affected by CVE-2026-8659?
Authenticated users of the Rapid7 InsightConnect SQLmap Plugin on Linux are affected by CVE-2026-8659.
5
What can attackers do with CVE-2026-8659?
Attackers exploiting CVE-2026-8659 can execute arbitrary OS commands due to insufficient input validation.