---
id: CVE-2026-75135
title: >-
  UpSignOn for Windows before 7.19.0 contains a sensitive data exposure
  vulnerability that allows local attackers to recover the master password and
  decrypt vault contents by reading a retained backup key from the process
  memory of UpSignO…
summary: >-
  UpSignOn for Windows before 7.19.0 contains a sensitive data exposure
  vulnerability that allows local attackers to recover the master password and
  decrypt vault contents by reading a retained backup key from the process
  memory of UpSignO…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-316
published: '2026-09-02'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:18:59.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75135'
references:
  - url: 'https://upsignon.eu/en/resources/release-notes/app#7.19.0'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/upsignon-sensitive-key-retention-in-memory
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00097
epssPercentile: 0.00694
ingestedAt: '2026-09-05T20:44:35.535Z'
---

## Overview

UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been re-locked. Attackers can extract the backup key from process memory to decrypt the encrypted master password backup stored in v6-vault1.DATA.txt, then use the recovered master password to decrypt the main vault and export all password manager entries in cleartext.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
