PT-2026-6046 · Rapid7 · Insightvm
CVE-2026-1568
·
Publicado
2026-02-03
·
Atualizado
2026-03-10
CVSS v3.1
9.6
Crítica
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Rapid7 InsightVM versions prior to 8.34.0
Description
Rapid7 InsightVM installations utilizing the "Security Console" setup are susceptible to a signature verification flaw on the Assertion Consumer Service (ACS) cloud endpoint. This issue allows an attacker to potentially gain unauthorized access to InsightVM accounts, leading to a full account takeover. The application processes unsigned assertions and issues session cookies, granting access to targeted user accounts.
Recommendations
Update to InsightVM version 8.34.0 or later.
Correção
Improper Verification of Cryptographic Signature
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Insightvm