CVE-2026-75135 Details
Description
UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been re-locked. Attackers can extract the backup key from process memory to decrypt the encrypted master password backup stored in v6-vault1.DATA.txt, then use the recovered master password to decrypt the main vault and export all password manager entries in cleartext.
A vulnerability in UpSignOn for Windows, prior to version 7.19.0, allows local attackers to recover the master password and decrypt vault contents. This is achieved by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been re-locked. The extracted backup key can be used to decrypt the encrypted master password backup stored in v6-vault1.DATA.txt. Once the master password is recovered, it can be used to decrypt the main vault and export all password manager entries in cleartext.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 2, 2026CISA-ADP
Assessed Sep 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://upsignon.eu/en/resources/release-notes/app#7.19.0 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/upsignon-sensitive-key-retention-in-memory | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-316 | Cleartext Storage of Sensitive Information in Memory | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| UpSignOn | < 7.19.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 5, 2026 | CVE Modified | CISA-ADP |
| Sep 2, 2026 | New CVE Received | [email protected] |
Volerion