CVE-2026-1814: RAPID7 Insightvm/nexpose

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassword.generateRandomPassword() method. When updating legacy keystore passwords, the application generates a new password with insufficient length (7-12 characters) and a static prefix 'p', resulting in a weak keyspace. An attacker with access to the nsc.ks file can brute-force this password using consumer-grade hardware to decrypt stored credentials.

Affected products

  • RAPID7 Insightvm/nexpose: from 6.4.50, before 8.36.0 (fixed in 8.36.0)

Published 2026-02-03. Last modified 2026-06-17.