CVE-2026-8666 | Rapid7 InsightConnect Traceroute Plugin up to 1.0.2 on Linux Request Parameter os command injection (EUVD-2026-39161)
A vulnerability labeled as critical has been found in Rapid7 InsightConnect Traceroute Plugin up to 1.0.2 on Linux. This issue affects some unknown processing of the component Request Parameter Handler. Such manipulation leads to os command injection.
This vulnerability is documented as CVE-2026-8666. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.