CVE-2026-1568
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
03/02/2026
Last modified:
03/02/2026
Description
Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup<br />
via "Security Console" installations, resulting in full account takeover. The issue occurs due to the application processing these unsigned assertions and issuing session cookies that granted access to the<br />
targeted user accounts. This has been fixed in version 8.34.0 of InsightVM.
Impact
Base Score 3.x
9.60
Severity 3.x
CRITICAL



