CVE Database
/

CVE-2026-1814

Back to search

CVE-2026-1814

Published: Feb 3, 2026

Modified: Feb 26, 2026

PUBLISHED

Description

Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassword.generateRandomPassword() method. When updating legacy keystore passwords, the application generates a new password with insufficient length (7-12 characters) and a static prefix 'p', resulting in a weak keyspace. An attacker with access to the nsc.ks file can brute-force this password using consumer-grade hardware to decrypt stored credentials.

VendorProductVersions

Rapid7

InsightVM/Nexpose

affected
6.4.50 - < 8.36.0

Weaknesses (CWE)

References

https://www.atredis.com/disclosure
exploit
third-party-advisory

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now