Sensitive Data Exposure in UpSignOn for Windows Affects Local Security
CVE-2026-75135

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-75135?

UpSignOn for Windows versions before 7.19.0 is vulnerable to a sensitive data exposure issue, enabling local attackers to retrieve the master password and access vault contents. This is possible by extracting a retained backup key from the memory of the UpSignOn.exe process, even after the vault has been re-locked. Attackers can utilize this backup key to decrypt the stored master password found in v6-vault1.DATA.txt, allowing them to access and export all entries from the password manager in clear text. This vulnerability underscores the importance of memory management and data protection in software applications.

Affected Version(s)

UpSignOn 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Elymaro (Aurélien Bourdois)
.