A vulnerability categorized as very critical has been discovered in Rapid7 InsightVM, Nexpose and Insight Agent. Affected by this vulnerability is an unknown functionality. The manipulation results in improper privilege management.
This vulnerability is identified as CVE-2026-14172. The attack is only possible with local access. There is not any exploit available.