Improper Key Management Vulnerability in Imprivata EAM Software
CVE-2026-82356
Currently unrated
What is CVE-2026-82356?
Imprivata EAM prior to version 26.2.6 exhibits a significant flaw in its key management practices, specifically lacking the capability to rotate RSA key pairs post-deployment. This oversight permits the indefinite use of a single RSA key pair for generating X.509 certificates, deviating from established best practices in cybersecurity. The failure to implement key rotation elevates the risk of potential exploitation, as attackers could compromise certificates generated with a static key pair over time.
Affected Version(s)
Imprivata Enterprise Access Management 0.0.0 <= 26.2.6
