CVE-2026-9155: OS Command Injection in Rapid7 InsightConnect Sed Plugin via expression parameter.
OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input validation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9155?
The severity of CVE-2026-9155 is rated high with a CVSS score of 8.8.
How do I fix CVE-2026-9155?
To fix CVE-2026-9155, ensure that the Rapid7 InsightConnect Sed Plugin is updated to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-9155?
CVE-2026-9155 is an OS Command Injection vulnerability that allows attackers to execute arbitrary OS commands.
Who is affected by CVE-2026-9155?
Authenticated users of the Rapid7 InsightConnect Sed Plugin on Linux systems are affected by CVE-2026-9155.
What causes the vulnerability in CVE-2026-9155?
CVE-2026-9155 is caused by insufficient input validation in the expression parameter of the Rapid7 InsightConnect Sed Plugin.