CVE-2026-82356
Received Received - Intake

Imprivata EAM RSA Key Pair Certificate Generation Vulnerability

Vulnerability report for CVE-2026-82356, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: CERT/CC

Description

Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate. Using an RSA key pair indefinitely for certificate generation is against best practices.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-24
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
imprivata eam to 26.2.6 (inc)
imprivata enterprise_access_management to 26.2.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Imprivata EAM versions 26.2.6 and below have a flaw where the RSA key pair used for generating X.509 certificates cannot be rotated after deployment. This means the same key pair is used indefinitely, which violates security best practices.

Impact Analysis

Using a static RSA key pair for certificate generation increases the risk of key compromise. If the key is exposed, attackers could impersonate the system, decrypt communications, or forge certificates, leading to potential data breaches or unauthorized access.

Compliance Impact

This vulnerability may violate compliance requirements that mandate regular cryptographic key rotation, such as NIST guidelines or industry-specific regulations like GDPR (data protection) and HIPAA (healthcare data). Failure to rotate keys could result in non-compliance penalties.

Mitigation Strategies

Rotate the RSA key pair used by Imprivata EAM to comply with best practices. Check the documentation for key rotation procedures and update to a version that supports automatic key rotation if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82356. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart