CVE-2026-8665: OS Command Injection in Rapid7 InsightConnect Translate Plugin
Published Jun 25, 2026
·Updated
OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command construction.
Affected Software
3 affected components
Rapid7 InsightConnect Translate Plugin
All of the following
Rapid7 Insightconnect Translate Rapid7<2.0.3
Linux Linux kernel
Event History
Jun 25, 2026
CVE Published
via MITRE·01:12 AM
Data Sourced
via MITRE·01:12 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeaknessAffected Software
Jul 25, 58465
Event
via FIRST·05:42 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-8665?
CVE-2026-8665 has a severity score of 7.7, indicating a high risk level.
2
How do I fix CVE-2026-8665?
To fix CVE-2026-8665, update the Rapid7 InsightConnect Translate Plugin to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2026-8665?
CVE-2026-8665 is classified as an OS Command Injection vulnerability.
4
What are the affected systems for CVE-2026-8665?
CVE-2026-8665 specifically affects the Rapid7 InsightConnect Translate Plugin on Linux systems.
5
What can attackers achieve through CVE-2026-8665?
Attackers can execute arbitrary OS commands remotely due to insufficient input sanitization in the plugin.