---
id: CVE-2026-92680
title: >-
  Araxis Merge for Windows version 2011.4074 through 2026.0 stores
  user-configured credentials for remote servers in the Windows registry and
  does not apply sufficient cryptographic protection
summary: >-
  Araxis Merge for Windows version 2011.4074 through 2026.0 stores
  user-configured credentials for remote servers in the Windows registry and
  does not apply sufficient cryptographic protection. An authenticated,
  non-administrative attacker…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-522
vendor: Araxis
product: Merge
affected:
  - Merge >= 2011.4074 < 2026.1
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T19:37:47.987'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92680'
references:
  - url: 'https://github.com/grepstrength/CVE-2026-92680'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://grepstrength.com/research/araxis-merge'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-267-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.araxis.com/merge/release-notes-2026#Merge-SA-26-00'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-92680'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - exploit-available
  - cve.org
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/grepstrength/CVE-2026-92680'
  checkedAt: '2026-09-26T09:06:06.119Z'
exploitAvailable: true
ingestedAt: '2026-09-24T15:45:56.674Z'
epss: 0.00165
epssPercentile: 0.05106
---

## Overview

Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
