SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-75137

MEDIUM · CVSS 6.1 EPSS 0.07%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

UpSignOn for Windows versions prior to 7.19.0 is vulnerable to sensitive data exposure, allowing local attackers to access cleartext vault data from process memory, even when the application is locked. This vulnerability enables the extraction of critical information such as usernames, passwords, and TOTP secrets using the PROCESS_VM_READ permission. Organizations using this application should prioritize updating to the latest version to mitigate the risk of data compromise.

CVE
CVE-2026-75137
Severity
MEDIUM
CVSS
6.1
EPSS
0.07%
Windows

Original NVD Description

UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after the application has been locked. Attackers can use the PROCESS_VM_READ permission to read the memory space of UpSignOn.exe and extract sensitive fields including entry names, URLs, usernames, passwords, TOTP secrets, and notes.