SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-75135

MEDIUM · CVSS 6.1 EPSS 0.07%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

UpSignOn for Windows versions prior to 7.19.0 is vulnerable to sensitive data exposure, allowing local attackers to extract the backup key from the process memory of UpSignOn.exe. This enables them to recover the master password and decrypt vault contents, potentially exposing all stored password manager entries in cleartext. Organizations using affected versions should prioritize this vulnerability to safeguard sensitive information against local threats.

CVE
CVE-2026-75135
Severity
MEDIUM
CVSS
6.1
EPSS
0.07%
Windows

Original NVD Description

UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been re-locked. Attackers can extract the backup key from process memory to decrypt the encrypted master password backup stored in v6-vault1.DATA.txt, then use the recovered master password to decrypt the main vault and export all password manager entries in cleartext.