๐Ÿ” CVE Alert

CVE-2026-1814

UNKNOWN 0.0

Rapid7 Nexpose Insecure Java Keystore Password Generation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassword.generateRandomPassword() method. When updating legacy keystore passwords, the application generates a new password with insufficient length (7-12 characters) and a static prefix 'p', resulting in a weak keyspace. An attacker with access to the nsc.ks file can brute-force this password using consumer-grade hardware to decrypt stored credentials.

CWE CWE-331
Vendor rapid7
Product insightvm/nexpose
Published Feb 3, 2026
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for rapid7 insightvm/nexpose

Be the first to know when new unknown vulnerabilities affecting rapid7 insightvm/nexpose are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Rapid7 / InsightVM/Nexpose
6.4.50 < 8.36.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
atredis.com: https://www.atredis.com/disclosure

Credits

Justin Kennedy Atredis Partners Stephen Breen Phil Brass