CVE-2026-4482 Details
Description
The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user.
A vulnerability exists in the Rapid7 Insight Agent for Windows, where installer certificate files in the bootstrap/common/ssl folder lack proper permission restrictions. This oversight allows read and execute access to all users, including standard users. The issue is particularly concerning for the client.key file, as it exposes agent identity material to locally authenticated standard users, potentially leading to exploits.
Users can update to Rapid7 Agent version 4.1.0.2, which restricts access to certain file paths on Windows installations, ensuring that sensitive files are only accessible by the SYSTEM user. This update also removes potential vulnerabilities related to the Python cryptography library and OpenSSL integration.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.rapid7.com/insight/release-notes-2026-april/#improvements-and-fixes | [email protected] | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rapid7 insight agent | < 4.1.0.2 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | Initial Analysis | [email protected] |
| Apr 10, 2026 | New CVE Received | [email protected] |