Description
UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after the application has been locked. Attackers can use the PROCESS_VM_READ permission to read the memory space of UpSignOn.exe and extract sensitive fields including entry names, URLs, usernames, passwords, TOTP secrets, and notes.
Published: 2026-09-02
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

UpSignOn for Windows prior to version 7.19.0 has a vulnerability that allows a local attacker to recover cleartext vault data from the application's process memory even after the user has locked the application. The flaw permits reading of sensitive fields such as entry names, URLs, usernames, passwords, TOTP secrets, and notes, effectively exposing all stored credentials and notes to the attacker.

Affected Systems

The affected product is Septeo IT Solutions' UpSignOn running on Windows environments. All installations using versions earlier than 7.19.0 are vulnerable, regardless of deployed platform configuration.

Risk and Exploitability

The vulnerability has a CVSS score of 6.9, denoting a medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Because it requires local access to the process and the PROCESS_VM_READ permission, the attack vector is local, and it will only be exploitable by an attacker who can execute code or otherwise gain permissions on the same machine. If the attacker can elevate privileges or bypass local security controls, they can read the memory space and retrieve all sensitive vault entries.

Generated by OpenCVE AI on September 3, 2026 at 09:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to UpSignOn version 7.19.0 or later to remove the memory‑exposure flaw.
  • Configure Windows Permissions to deny the READ PROCESS IMAGES privilege to local users or the account running the application, thereby preventing read access to the process memory through PROCESS_VM_READ.
  • Apply general least‑privilege hardening: run the application under a restricted service account with no unnecessary local rights and monitor for unauthorized memory‑read attempts.

Generated by OpenCVE AI on September 3, 2026 at 09:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Septeo It Solutions
Septeo It Solutions upsignon
Vendors & Products Septeo It Solutions
Septeo It Solutions upsignon

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after the application has been locked. Attackers can use the PROCESS_VM_READ permission to read the memory space of UpSignOn.exe and extract sensitive fields including entry names, URLs, usernames, passwords, TOTP secrets, and notes.
Title UpSignOn < 7.19.0 Sensitive Data Exposure in Process Memory after Lock
Weaknesses CWE-316
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Septeo It Solutions Upsignon
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-03T14:31:13.657Z

Reserved: 2026-08-17T18:39:57.661Z

Link: CVE-2026-75137

cve-icon Vulnrichment

Updated: 2026-09-03T14:05:22.256Z

cve-icon NVD

Status : Received

Published: 2026-09-02T20:17:37.033

Modified: 2026-09-03T15:17:33.140

Link: CVE-2026-75137

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:33:49Z

Weaknesses
  • CWE-316

    Cleartext Storage of Sensitive Information in Memory