CVE-2026-75137

UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after the application has been locked. Attackers can use the PROCESS_VM_READ permission to read the memory space of UpSignOn.exe and extract sensitive fields including entry names, URLs, usernames, passwords, TOTP secrets, and notes.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 20:17

Updated : 2026-09-08 20:18


NVD link : CVE-2026-75137

Mitre link : CVE-2026-75137

CVE.ORG link : CVE-2026-75137


JSON object : View

Products Affected

No product.

CWE
CWE-316

Cleartext Storage of Sensitive Information in Memory