CVE-2026-75135
Received Received - Intake

UpSignOn for Windows Sensitive Data Exposure via Process Memory

Vulnerability report for CVE-2026-75135, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: VulnCheck

Description

UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been re-locked. Attackers can extract the backup key from process memory to decrypt the encrypted master password backup stored in v6-vault1.DATA.txt, then use the recovered master password to decrypt the main vault and export all password manager entries in cleartext.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-03
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
upsignon upsignon to 7.19.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-316 The product stores sensitive information in cleartext in memory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

UpSignOn for Windows before 7.19.0 has a vulnerability where a backup key remains in the process memory of UpSignOn.exe even after the vault is re-locked. Attackers can extract this backup key to decrypt the encrypted master password backup stored in a file named v6-vault1.DATA.txt. The recovered master password can then be used to decrypt the main vault and export all password manager entries in plaintext.

Detection Guidance

To detect this vulnerability, monitor for suspicious process memory access or unusual file reads targeting UpSignOn.exe or v6-vault1.DATA.txt. Check for unauthorized decryption attempts or plaintext password exports. Use tools like Process Explorer or WinDbg to inspect memory contents of UpSignOn.exe for retained backup keys.

Impact Analysis

If you use UpSignOn for Windows versions before 7.19.0, a local attacker with low privileges could recover your master password and decrypt all stored passwords. This could lead to unauthorized access to sensitive information, identity theft, or data breaches.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations using affected versions may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Immediately upgrade UpSignOn for Windows to version 7.19.0 or later to patch the vulnerability. If upgrading is not possible, restrict local user access to systems running UpSignOn and monitor for unauthorized memory access. Avoid storing sensitive data in plaintext and review system logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75135. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart