CVE-2026-1568

Rapid7 InsightVM versions beforeĀ 8.34.0 contain a signature verification issue on theĀ Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup via "Security Console" installations, resulting in full account takeover. The issue occurs due to the application processing these unsigned assertions and issuing session cookies that granted access to the targeted user accounts. This has been fixed in version 8.34.0 of InsightVM.
Configurations

No configuration.

History

03 Feb 2026, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 17:15

Updated : 2026-02-03 17:15


NVD link : CVE-2026-1568

Mitre link : CVE-2026-1568

CVE.ORG link : CVE-2026-1568


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication

CWE-347

Improper Verification of Cryptographic Signature