PT-2026-84857 · Upsignon · Upsignon

·

CVE-2026-75135

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions UpSignOn for Windows versions prior to 7.19.0
Description A sensitive data exposure issue exists where local attackers can recover the master password and decrypt vault contents. This is possible by reading a retained backup key from the process memory of UpSignOn.exe, which remains accessible even after the vault has been re-locked. Attackers can use this backup key to decrypt the encrypted master password backup stored in v6-vault1.DATA.txt, subsequently using the recovered master password to decrypt the main vault and export all password manager entries in cleartext.
Recommendations Update to version 7.19.0 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75135

Affected Products

Upsignon