CVE-2026-1568Disclosure

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup via "Security Console" installations, resulting in full account takeover. The issue occurs due to the application processing these unsigned assertions and issuing session cookies that granted access to the targeted user accounts. This has been fixed in version 8.34.0 of InsightVM.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-03); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-03: 3Mentions · 2026-02-04: 1Patch / Workaround · 2026-02-03: 1Technical Details · 2026-02-03: 3Technical Details · 2026-02-04: 102-0302-04
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-033
Disclosure2Patch1
2026-02-041
Disclosure1
Full discourse4 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical signature verification issue in #Rapid7 InsightVM. CVE-2026-1568 CVSS: 9.6. This can allow attackers to gain unauthorized access and perform a full account takeover #ATO! #Patch #Patch #Patch

    Post summary

    Rapid7 InsightVM has a critical signature verification flaw (CVE‑2026‑1568, CVSS 9.6) that could allow full account takeover, but no patch details or exploit code are provided.

    01000252
    7.2K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-1568: CRITICAL] Critical security update: Rapid7 InsightVM fixed a signature verification issue on ACS cloud endpoint in versions prior to 8.34.0, preventing unauthorized access & full account takeover.#cve,CVE-2026-1568,#cybersecurity https://cvefind.com/CVE-2026-1568

    Post summary

    Rapid7 InsightVM released a patch for CVE‑2026‑1568, addressing a critical signature verification flaw that could allow full account takeover on ACS cloud endpoints.

    0000078
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-1568 - Critical Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized ac... https://www.thehackerwire.com/vulnerability/CVE-2026-1568/ https://t.co/HfqhZcsKsK

    Post summary

    Rapid7 InsightVM versions before 8.34.0 suffer a signature verification flaw on the ACS cloud endpoint that could enable unauthorized access, but no PoC, exploit, or patch information is provided.

    0000082
    113 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1568: Rapid7 InsightVM Signature Valida... Missing SAML signature validation in Rapid7 InsightVM's ACS endpoint gives attackers full account takeover with minimal ... https://zerodaysignal.com/vulnerability/CVE-2026-1568 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-1568 highlights a missing SAML signature validation in Rapid7 InsightVM that enables attackers to fully takeover accounts.

    0000057
    132 followersView on X

Explore more