OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processing pipeline.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://extensions.rapid7.com/extension/awk |
|
History
Fri, 26 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rapid7
Rapid7 insightconnect Awk Plugin |
|
| Vendors & Products |
Rapid7
Rapid7 insightconnect Awk Plugin |
Thu, 25 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 25 Jun 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processing pipeline. | |
| Title | OS Command Injection in Rapid7 InsightConnect AWK Plugin | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: rapid7
Published: 2026-06-25T01:32:22.119Z
Updated: 2026-06-25T13:38:34.797Z
Reserved: 2026-05-14T08:24:20.479Z
Link: CVE-2026-8592
Updated: 2026-06-25T13:36:00.277Z
No data.
No data.
ReportizFlow