CVE-2026-1568
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-287
Autenticación incorrecta
Fecha de publicación:
03/02/2026
Última modificación:
04/02/2026
Descripción
*** Pendiente de traducción *** Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup<br />
via "Security Console" installations, resulting in full account takeover. The issue occurs due to the application processing these unsigned assertions and issuing session cookies that granted access to the<br />
targeted user accounts. This has been fixed in version 8.34.0 of InsightVM.
Impacto
Puntuación base 3.x
9.60
Gravedad 3.x
CRÍTICA



