CVE-2026-1568

CRITICAL

Rapid7 InsightVM <8.34.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup via "Security Console" installations, resulting in full account takeover. The issue occurs due to the application processing these unsigned assertions and issuing session cookies that granted access to the targeted user accounts. This has been fixed in version 8.34.0 of InsightVM.

Scores

CVSS v3 9.6
EPSS 0.0002
EPSS Percentile 5.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287 CWE-347
Status published
Products (1)
Rapid7/Vulnerability Management < 8.34.0
Published Feb 03, 2026
Tracked Since Feb 18, 2026