The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Apr 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user. | |
| Title | Insight Agent Private Key Information Disclosure via Inherited File Permissions | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-04-10T04:22:38.719Z
Reserved: 2026-03-20T05:21:38.041Z
Link: CVE-2026-4482
No data.
Status : Received
Published: 2026-04-10T05:16:04.587
Modified: 2026-04-10T05:16:04.587
Link: CVE-2026-4482
No data.