PT-2026-97505 · Imprivata · Imprivata Eam

CVE-2026-82356

·

Published

2026-09-23

·

Updated

2026-09-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Imprivata EAM versions prior to 26.2.7
Description The software lacks a mechanism to rotate the RSA key pair used for generating X.509 certificates after deployment. This means the key pair remains permanent once the system is deployed, which contradicts security best practices. If the private key is compromised through methods such as backup exfiltration, hypervisor snapshots, or privileged filesystem access, an attacker can maintain a valid appliance identity indefinitely because no revocation mechanism exists other than a full redeployment. This issue affects environments relying on the system for Single Sign-On (SSO), including clinical workstations and EHR platforms.
Recommendations Update to a version newer than 26.2.6. Treat the appliance filesystem and backups as Tier 0 assets. Restrict access to hypervisor snapshots and monitor for unauthorized reads of key files. Perform a controlled redeployment of the appliance to generate a fresh key pair.

Fix

Inadequate Encryption Strength

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82356

Affected Products

Imprivata Eam