MEDIUM
CVE-2026-9154
CVSS
6.5
Description
Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression parameter.
Summary dbcve.org
Arbitrary File Write vulnerability in the Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths by manipulating the expression parameter, potentially leading to code execution or system compromise.
Mitigation
Implement strict input validation and path sanitization on the expression parameter to prevent path traversal and restrict write operations to intended directories; also apply principle of least privilege to plugin permissions.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
0.41%
Probability of exploitation in next 30 days
34.9th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.