Sensitive Data Exposure in UpSignOn for Windows by UpSignOn
CVE-2026-75137
6.9MEDIUM
What is CVE-2026-75137?
UpSignOn for Windows, prior to version 7.19.0, is vulnerable to a sensitive data exposure flaw that allows local attackers to recover cleartext vault data. Even when the application is locked, unauthorized users can leverage the PROCESS_VM_READ permission to access the memory space of the UpSignOn.exe process. This exploitation can lead to the exposure of critical information such as entry names, URLs, usernames, passwords, TOTP secrets, and additional notes, thereby compromising sensitive user data.
Affected Version(s)
UpSignOn 0
