Junglewise Threat Intelligence

CVE-2026-75135: UpSignOn for Windows sensitive data exposure in memory

CVE-2026-75135 · Severity: medium · CVSS 6.1 · Published 2026-09-02

Technologies: UpSignOn for Windows. Vendors: UpSignOn.

Executive brief

UpSignOn is a password manager application for Windows that encrypts and stores user credentials in a vault. A vulnerability in versions before 7.19.0 allows local attackers with user-level access to extract the master password from the application's memory, even after the vault is locked. An attacker exploiting this flaw could decrypt and export all stored passwords and sensitive data in plaintext.

Technical details

The vulnerability stems from improper memory handling in UpSignOn.exe, where a backup encryption key is retained in process memory and not securely cleared after use. An attacker with local access and standard user privileges can read the process memory to extract this backup key, then use it to decrypt the master password backup stored in the v6-vault1.DATA.txt file. Once the master password is recovered, the attacker can unlock the entire vault and export all stored credentials. This is a cleartext storage in memory vulnerability (CWE-316) that requires local access but can be performed without administrator rights or user interaction.

Affected products

  • UpSignOn UpSignOn for Windows before 7.19.0

Timeline

  • 2026-09-02: disclosed
  • 2026-08-05: patched: Version 7.19.0 released with security fixes

References

Related threats