Improper Key Management Vulnerability in Imprivata EAM Software
CVE-2026-82356

Currently unrated

Key Information:

Vendor

Imprivata

Vendor
CVE Published:
23 September 2026

What is CVE-2026-82356?

Imprivata EAM prior to version 26.2.6 exhibits a significant flaw in its key management practices, specifically lacking the capability to rotate RSA key pairs post-deployment. This oversight permits the indefinite use of a single RSA key pair for generating X.509 certificates, deviating from established best practices in cybersecurity. The failure to implement key rotation elevates the risk of potential exploitation, as attackers could compromise certificates generated with a static key pair over time.

Affected Version(s)

Imprivata Enterprise Access Management 0.0.0 <= 26.2.6

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.