Sploitus

CVE-2026-1814

1 known exploit for CVE-2026-1814

Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassword.generateRandomPassword() method. When updating legacy keystore passwords, the application generates a new password with insufficient length (7-12 characters) and a static prefix 'p', resulting in a weak keyspace. An attacker with access to the nsc.ks file can brute-force this password using consumer-grade hardware to decrypt stored credentials.

Affected products
Rapid7 Nexpose
CVSS 4.0
6.8 MEDIUM
EPSS
0.1% (4th percentile)
Weakness
CWE-331
NVD status
Deferred
Published
2026-02-03
Attack patterns
CAPEC-112

Fix

InsightVM or Nexpose customers with automatic product updates enabled will receive and process this update when it is released. Customers who manually control their own update version can utilize the manual update process within the security console to update to version 8.36.0 when it is made available. We recommend those customers schedule this update as soon as reasonably possible.

CVE-2026-1814 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-1814

Proof-of-concept code and exploit modules indexed by Sploitus