{"id":"CVE-2026-92680","title":"Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection","summary":"Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-522"],"vendor":"Araxis","product":"Merge","affected":["Merge >= 2011.4074 < 2026.1"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T19:37:47.987","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92680","references":[{"url":"https://github.com/grepstrength/CVE-2026-92680","label":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://grepstrength.com/research/araxis-merge","label":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-267-01.json","label":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://www.araxis.com/merge/release-notes-2026#Merge-SA-26-00","label":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-92680","label":"9119a7d8-5eab-497f-8521-727c672e3725"}],"tags":["nvd","exploit-available","cve.org"],"exploits":{"github":1,"githubRepos":["https://github.com/grepstrength/CVE-2026-92680"],"checkedAt":"2026-09-24T19:51:05.132Z"},"exploitAvailable":true,"ingestedAt":"2026-09-24T15:45:56.674Z","slug":"CVE-2026-92680","body":"## Overview\n\nAraxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}