CVE Explorer
CVE-2026-7373
Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When started the metasploitPostgreSQL service would start the postgres.exe child process which would in turn load an OpenSSL configuration file from a static location. This static location would be writable by a pre-existing "vagrant" user, if they already existed on the system. Metasploit does not create local accounts, an Administrator would need to crea
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-829","description":"CWE-829 Inclusion of Functionality from Untrusted Control Sphere","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1a5ab2cf9f0b8ddfcb1b0399a1d2e26862ceb34a58deaa4c7b9a7f2ba09250db · sha256:e94ae768029d2c7b… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-427","description":"CWE-427 Uncontrolled Search Path Element","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1a5ab2cf9f0b8ddfcb1b0399a1d2e26862ceb34a58deaa4c7b9a7f2ba09250db · sha256:e94ae768029d2c7b… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1a5ab2cf9f0b8ddfcb1b0399a1d2e26862ceb34a58deaa4c7b9a7f2ba09250db · sha256:e94ae768029d2c7b… · /containers/cna/problemTypes/2/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","platforms":["Windows"],"product":"Metasploit Pro","vendor":"Rapid7","versions":[{"status":"affected","version":"5.0.0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1a5ab2cf9f0b8ddfcb1b0399a1d2e26862ceb34a58deaa4c7b9a7f2ba09250db · sha256:e94ae768029d2c7b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":8.5,"baseSeverity":"HIGH","exploitMaturity":"PROOF_OF_CONCEPT","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H/E:P","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImp…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:1a5ab2cf9f0b8ddfcb1b0399a1d2e26862ceb34a58deaa4c7b9a7f2ba09250db · sha256:e94ae768029d2c7b… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
3 source assertions{"cweId":"CWE-829","description":"CWE-829 Inclusion of Functionality from Untrusted Control Sphere","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1a5ab2cf9f0b8ddfcb1b0399a1d2e26862ceb34a58deaa4c7b9a7f2ba09250db · sha256:e94ae768029d2c7b… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-427","description":"CWE-427 Uncontrolled Search Path Element","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1a5ab2cf9f0b8ddfcb1b0399a1d2e26862ceb34a58deaa4c7b9a7f2ba09250db · sha256:e94ae768029d2c7b… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1a5ab2cf9f0b8ddfcb1b0399a1d2e26862ceb34a58deaa4c7b9a7f2ba09250db · sha256:e94ae768029d2c7b… · /containers/cna/problemTypes/2/descriptions/0
Source references
1 source assertion{"name":"Similar CVE Reference","tags":["release-notes"],"url":"https://docs.rapid7.com/insight/release-notes-5.0.0-2026051301/#:~:text=Pro%3A%20We%20fixed,vulnerability%20to%20Rapid7."}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1a5ab2cf9f0b8ddfcb1b0399a1d2e26862ceb34a58deaa4c7b9a7f2ba09250db · sha256:e94ae768029d2c7b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.