Upsignon · Upsignon · CVE-2026-75137
**Name of the Vulnerable Software and Affected Versions**
UpSignOn for Windows versions prior to 7.19.0
**Description**
A sensitive data exposure issue exists that allows local attackers to recover cleartext vault data from process memory, even when the application is locked. By utilizing the `PROCESS VM READ` permission, an attacker can read the memory space of the `UpSignOn.exe` process to extract sensitive information, including entry names, URLs, usernames, passwords, TOTP secrets, and notes.
**Recommendations**
Update UpSignOn for Windows to version 7.19.0 or later.