MEDIUM
CVE-2026-9153
CVSS
6.5
Description
Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient input validation.
Summary dbcve.org
The Rapid7 InsightConnect Sed Plugin on Linux contains an arbitrary file read vulnerability that allows authenticated attackers to read any file on the host system through the expression parameter due to insufficient input validation.
Mitigation
Apply vendor patches/updates to the InsightConnect Sed Plugin and implement strict input validation on the expression parameter to prevent path traversal.
Weakness (CWE)
CWE-22
Path Traversal
CWE-200
Information Exposure
EPSS Score
0.45%
Probability of exploitation in next 30 days
38.7th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.