Sensitive Data Exposure in UpSignOn for Windows Affects Local Security
CVE-2026-75135
6.9MEDIUM
What is CVE-2026-75135?
UpSignOn for Windows versions before 7.19.0 is vulnerable to a sensitive data exposure issue, enabling local attackers to retrieve the master password and access vault contents. This is possible by extracting a retained backup key from the memory of the UpSignOn.exe process, even after the vault has been re-locked. Attackers can utilize this backup key to decrypt the stored master password found in v6-vault1.DATA.txt, allowing them to access and export all entries from the password manager in clear text. This vulnerability underscores the importance of memory management and data protection in software applications.
Affected Version(s)
UpSignOn 0
