CVE-2026-9154: Arbitrary File Write in Rapid7 InsightConnect Sed Plugin
Published Jun 25, 2026
·Updated
Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression parameter.
Affected Software
3 affected components
Rapid7 InsightConnect Sed Plugin
All of the following
GNU Sed=4.2.2
Linux Linux kernel
Event History
Jun 25, 2026
CVE Published
via MITRE·12:29 AM
Data Sourced
via MITRE·12:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeaknessAffected Software
Feb 1, 58460
Event
via FIRST·03:45 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-9154?
The severity of CVE-2026-9154 is classified as high with a CVSS score of 7.1.
2
How do I fix CVE-2026-9154?
To fix CVE-2026-9154, update the Rapid7 InsightConnect Sed Plugin to the latest version that addresses the vulnerability.
3
What type of attack does CVE-2026-9154 enable?
CVE-2026-9154 enables authenticated attackers to conduct arbitrary file write attacks on Linux systems.
4
What parameters are involved in the CVE-2026-9154 vulnerability?
The expression parameter is involved in the CVE-2026-9154 vulnerability, allowing attackers to manipulate file paths.
5
What impact does CVE-2026-9154 have on affected systems?
CVE-2026-9154 can lead to unauthorized modification of files, compromising system integrity.