Sensitive Data Exposure in UpSignOn for Windows by UpSignOn
CVE-2026-75137

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-75137?

UpSignOn for Windows, prior to version 7.19.0, is vulnerable to a sensitive data exposure flaw that allows local attackers to recover cleartext vault data. Even when the application is locked, unauthorized users can leverage the PROCESS_VM_READ permission to access the memory space of the UpSignOn.exe process. This exploitation can lead to the exposure of critical information such as entry names, URLs, usernames, passwords, TOTP secrets, and additional notes, thereby compromising sensitive user data.

Affected Version(s)

UpSignOn 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Elymaro (Aurélien Bourdois)
.