Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-75135— UpSignOn < 7.19.0 Sensitive Key Retention in Memory

Quick assessment

Affected
Septeo IT Solutions UpSignOn
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Windows 版 UpSignOn 在 7.19.0 之前存在敏感数据暴露漏洞。本地攻击者即使金库已重新锁定,也能通过读取 UpSignOn.exe 进程内存中保留的备份密钥,恢复主密码并解密金库内容。具体而言,攻击者可以从进程内存中提取该备份密钥,用于解密存储在 v6-vault1.DATA.txt 中的加密主密码备份,进而利用恢复出的主密码解密主金库,并将所有密码管理器条目以明文形式导出。

CVSS 6.1 · Medium EPSS 0.07% · P0

Affected Version Matrix 1

VendorProduct Version RangeStatus
Septeo IT Solutions UpSignOn < 7.19.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-75135

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
UpSignOn < 7.19.0 Sensitive Key Retention in Memory
Source: CVE Program / CVE List V5
Vulnerability Description
UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been re-locked. Attackers can extract the backup key from process memory to decrypt the encrypted master password backup stored in v6-vault1.DATA.txt, then use the recovered master password to decrypt the main vault and export all password manager entries in cleartext.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在内存中的明文存储
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Septeo IT Solutions UpSignOn 0 ~ 7.19.0 -

II. Public POCs for CVE-2026-75135

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-75135

登录查看更多情报信息。

Vendor Advisories for CVE-2026-75135 (1)

Vendor Pages for CVE-2026-75135 (1)

Same Patch Batch · Septeo IT Solutions · 2026-09-02 · 3 CVEs total

CVE-2026-75137 6.1 MEDIUM UpSignOn < 7.19.0 Sensitive Data Exposure in Process Memory after Lock
CVE-2026-75136 6.1 MEDIUM UpSignOn < 7.19.0 Biometric Key Exposure via Windows PasswordVault

IV. Related Vulnerabilities

V. Comments for CVE-2026-75135

No comments yet


Leave a comment