Description
UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been re-locked. Attackers can extract the backup key from process memory to decrypt the encrypted master password backup stored in v6-vault1.DATA.txt, then use the recovered master password to decrypt the main vault and export all password manager entries in cleartext.
Published: 2026-09-02
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

UpSignOn for Windows versions prior to 7.19.0 contains a flaw that lets a local attacker recover the master password by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been re‑locked. By extracting the backup key from memory, the attacker can decrypt the encrypted master password backup stored in v6-vault1.DATA.txt and then use that master password to decrypt the main vault and export all stored password manager entries in clear text. This vulnerability is categorized as sensitive data exposure (CWE‑316).

Affected Systems

The vulnerability affects Septeo IT Solutions' UpSignOn product on Windows. All UpSignOn installations with a version number lower than 7.19.0 are vulnerable. No additional affected versions are listed beyond the pre‑7.19.0 threshold.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, but the vulnerability requires local access to the machine running UpSignOn.exe. An attacker who can read process memory—such as a user with administrative privileges or one who can execute memory‑dumping tools—can exploit the flaw. The exploitation does not require network access or remote code execution; it is limited to local attackers with sufficient privileges. The lack of an EPSS score and the absence from the CISA KEV catalog suggest that while the vulnerability is not currently widely exploited, it presents a significant risk if local access is achieved.

Generated by OpenCVE AI on September 3, 2026 at 09:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to UpSignOn version 7.19.0 or newer, which removes the memory retention flaw.
  • Restrict local user privileges so that only trusted administrators can access UpSignOn’s process memory, minimizing the risk of in‑memory key extraction.
  • Implement monitoring for anomalous memory‑dump activity against UpSignOn.exe to detect potential exploitation attempts.

Generated by OpenCVE AI on September 3, 2026 at 09:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Septeo It Solutions
Septeo It Solutions upsignon
Vendors & Products Septeo It Solutions
Septeo It Solutions upsignon

Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been re-locked. Attackers can extract the backup key from process memory to decrypt the encrypted master password backup stored in v6-vault1.DATA.txt, then use the recovered master password to decrypt the main vault and export all password manager entries in cleartext.
Title UpSignOn < 7.19.0 Sensitive Key Retention in Memory
Weaknesses CWE-316
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Septeo It Solutions Upsignon
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-05T01:05:57.799Z

Reserved: 2026-08-17T18:39:57.661Z

Link: CVE-2026-75135

cve-icon Vulnrichment

Updated: 2026-09-05T01:05:53.404Z

cve-icon NVD

Status : Received

Published: 2026-09-02T20:17:36.720

Modified: 2026-09-05T01:16:49.340

Link: CVE-2026-75135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:33:52Z

Weaknesses
  • CWE-316

    Cleartext Storage of Sensitive Information in Memory