CVE-2026-16895 | Rapid7 Metasploit Framework up to 6.5.1 JSON-RPC web service interface improper authentication
A vulnerability identified as critical has been detected in Rapid7 Metasploit Framework up to 6.5.1. Affected by this vulnerability is an unknown functionality of the component JSON-RPC web service interface. This manipulation causes improper authentication.
This vulnerability is registered as CVE-2026-16895. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.VulDB Recent EntriesRead More