PT-2026-97505 · Imprivata · Imprivata Eam
CVE-2026-82356
·
Published
2026-09-23
·
Updated
2026-09-25
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Imprivata EAM versions prior to 26.2.7
Description
The software lacks a mechanism to rotate the RSA key pair used for generating X.509 certificates after deployment. This means the key pair remains permanent once the system is deployed, which contradicts security best practices. If the private key is compromised through methods such as backup exfiltration, hypervisor snapshots, or privileged filesystem access, an attacker can maintain a valid appliance identity indefinitely because no revocation mechanism exists other than a full redeployment. This issue affects environments relying on the system for Single Sign-On (SSO), including clinical workstations and EHR platforms.
Recommendations
Update to a version newer than 26.2.6.
Treat the appliance filesystem and backups as Tier 0 assets.
Restrict access to hypervisor snapshots and monitor for unauthorized reads of key files.
Perform a controlled redeployment of the appliance to generate a fresh key pair.
Fix
Inadequate Encryption Strength
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Imprivata Eam