CVE-2026-92680
Awaiting Analysis Awaiting Analysis - Queue

Araxis Merge Credential Exposure via Weak Registry Encryption

Vulnerability report for CVE-2026-92680, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
araxis merge 2011.4074
araxis merge 2026.0
araxis merge From 2011.4074 (inc) to 2026.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Araxis Merge for Windows versions 2011.4074 through 2026.0. It involves the application storing user-configured credentials for remote servers in the Windows registry without sufficient cryptographic protection. The credentials are encrypted using Windows DPAPI but with pOptionalEntropy set to NULL, allowing any code running under the same user account to decrypt and recover the stored credentials in plaintext.

Detection Guidance

Check the Windows Registry for stored credentials under HKCU\Software\Araxis\Merge\7.1\Passwords. Use PowerShell or reg query commands to inspect this path. Look for encrypted blobs that may be decrypted by any process in the same user context.

Impact Analysis

An authenticated, non-administrative attacker with local access to the machine could retrieve and decrypt all credentials stored by the target user in Araxis Merge. This could lead to unauthorized access to remote servers, lateral movement within enterprise environments, and potential data breaches if the compromised credentials grant access to sensitive systems or data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR (data protection) and HIPAA (health information privacy). Organizations using affected versions of Araxis Merge risk non-compliance due to insufficient protection of stored credentials, potentially resulting in data breaches and regulatory penalties.

Mitigation Strategies

Upgrade Araxis Merge to version 2026.1 or later immediately. Remove stored credentials from the registry if upgrading is not possible. Ensure no legacy credential storage remains under the affected registry path.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92680. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart