CVE-2026-1814
Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassword.generateRandomPassword() method. When updating legacy keystore passwords, the application generates a new password with insufficient length (7-12 characters) and a static prefix 'p', resulting in a weak keyspace. An attacker with access to the nsc.ks file can brute-force this password using consumer-grade hardware to decrypt stored credentials.
- Affected products
- Rapid7 Nexpose
- CVSS 4.0
- 6.8 MEDIUM
- EPSS
- 0.1% (4th percentile)
- Weakness
- CWE-331
- NVD status
- Deferred
- Published
- 2026-02-03
- Attack patterns
- CAPEC-112
Fix
InsightVM or Nexpose customers with automatic product updates enabled will receive and process this update when it is released. Customers who manually control their own update version can utilize the manual update process within the security console to update to version 8.36.0 when it is made available. We recommend those customers schedule this update as soon as reasonably possible.
1 known exploit for CVE-2026-1814
Proof-of-concept code and exploit modules indexed by Sploitus