Windows 版 UpSignOn 在 7.19.0 之前存在敏感数据暴露漏洞。本地攻击者即使金库已重新锁定,也能通过读取 UpSignOn.exe 进程内存中保留的备份密钥,恢复主密码并解密金库内容。具体而言,攻击者可以从进程内存中提取该备份密钥,用于解密存储在 v6-vault1.DATA.txt 中的加密主密码备份,进而利用恢复出的主密码解密主金库,并将所有密码管理器条目以明文形式导出。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Septeo IT Solutions | UpSignOn | < 7.19.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Septeo IT Solutions | UpSignOn | 0 ~ 7.19.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75137 | 6.1 MEDIUM | UpSignOn < 7.19.0 Sensitive Data Exposure in Process Memory after Lock |
| CVE-2026-75136 | 6.1 MEDIUM | UpSignOn < 7.19.0 Biometric Key Exposure via Windows PasswordVault |
No comments yet