CVE-2026-1814
Rapid7 Nexpose Insecure Java Keystore Password Generation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassword.generateRandomPassword() method. When updating legacy keystore passwords, the application generates a new password with insufficient length (7-12 characters) and a static prefix 'p', resulting in a weak keyspace. An attacker with access to the nsc.ks file can brute-force this password using consumer-grade hardware to decrypt stored credentials.
| CWE | CWE-331 |
| Vendor | rapid7 |
| Product | insightvm/nexpose |
| Published | Feb 3, 2026 |
| Last Updated | Feb 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for rapid7 insightvm/nexpose
Be the first to know when new unknown vulnerabilities affecting rapid7 insightvm/nexpose are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Rapid7 / InsightVM/Nexpose
6.4.50 < 8.36.0
Credits
Justin Kennedy Atredis Partners Stephen Breen Phil Brass