Description
Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate. Using an RSA key pair indefinitely for certificate generation is against best practices.
Published: 2026-09-23
Score: n/a
EPSS: n/a
KEV: No
Impact: Key lifecycle weakness
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in Imprivata Enterprise Access Management’s inability to rotate its RSA key pair after deployment when it generates an X.509 certificate. Because the same key pair is used indefinitely, the system does not adhere to best practices of cryptographic key management. This creates a risk that a compromised private key could be used to forge trusted certificates, enabling unauthorized authentication or the injection of false identities over time.

Affected Systems

Products affected are Imprivata Enterprise Access Management for all versions up to and including 26.2.6. The vulnerability was reported for releases 26.2.6 and earlier, which lack a mechanism to generate a new RSA key pair after the initial deployment.

Risk and Exploitability

No CVSS score is provided, and EPSS data is unavailable, so the quantified risk is not stated. The vulnerability does not describe an immediate active exploit path; rather, it exposes a long‑term risk by allowing an attacker who obtains the static key to create valid certificates. The lack of a KEV listing indicates no known exploits have been observed. The likely attack vector would be an internal actor or a compromised system with access to the key material, which can then produce genuine certificates. Until a patch is applied, the exposed risk remains a potential for future credential compromise.

Generated by OpenCVE AI on September 23, 2026 at 19:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Imprivata Enterprise Access Management to the latest release that supports RSA key rotation (26.2.7 or newer).
  • If an upgrade is not possible immediately, request a temporary RSA key pair from Imprivata support and replace the existing key via the administrative console, following vendor instructions.
  • Establish a key lifecycle policy that enforces rotation every 90 days, monitors for unusual certificate issuance, and logs all key usage events.

Generated by OpenCVE AI on September 23, 2026 at 19:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
References

Wed, 23 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-322

Wed, 23 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate. Using an RSA key pair indefinitely for certificate generation is against best practices.
Title Imprivata EAM: Unrotatable X.509 RSA Key Pair in Production
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-09-23T19:06:58.517Z

Reserved: 2026-08-28T18:04:06.099Z

Link: CVE-2026-82356

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T19:19:34.620

Modified: 2026-09-23T20:17:16.150

Link: CVE-2026-82356

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T20:00:08Z

Weaknesses
  • CWE-322

    Key Exchange without Entity Authentication