CVE-2026-75137
Received Received - Intake

Sensitive Data Exposure in UpSignOn for Windows

Vulnerability report for CVE-2026-75137, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: VulnCheck

Description

UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after the application has been locked. Attackers can use the PROCESS_VM_READ permission to read the memory space of UpSignOn.exe and extract sensitive fields including entry names, URLs, usernames, passwords, TOTP secrets, and notes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
upsignon upsignon to 7.19.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-316 The product stores sensitive information in cleartext in memory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

UpSignOn for Windows before version 7.19.0 has a vulnerability where sensitive data stored in process memory is exposed even after the application is locked. Local attackers with PROCESS_VM_READ permissions can read the memory of UpSignOn.exe to extract sensitive information like entry names, URLs, usernames, passwords, TOTP secrets, and notes.

Detection Guidance

To detect this vulnerability, check if UpSignOn for Windows versions before 7.19.0 are installed. Use tasklist or ps to verify if UpSignOn.exe is running. Monitor process memory for unauthorized access attempts using tools like Process Explorer or WinDbg.

Impact Analysis

This vulnerability allows local attackers to access sensitive data such as passwords and usernames stored in UpSignOn. If exploited, it could lead to unauthorized access to accounts, data breaches, or identity theft depending on the stored information.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized exposure of sensitive personal or health-related data. Organizations may face legal penalties, fines, or reputational damage if such data is compromised.

Mitigation Strategies

Immediately update UpSignOn for Windows to version 7.19.0 or later to patch the vulnerability. Restrict PROCESS_VM_READ permissions for untrusted users. Avoid storing sensitive data in memory longer than necessary.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75137. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart