Junglewise Threat Intelligence

CVE-2026-75136: UpSignOn for Windows insecure credential storage

CVE-2026-75136 · Severity: medium · CVSS 6.1 · Published 2026-09-02

Technologies: UpSignOn for Windows. Vendors: UpSignOn.

Executive brief

UpSignOn is a password manager application for Windows that stores authentication credentials and biometric unlock keys. A vulnerability before version 7.19.0 allows a local attacker to retrieve the biometric key without authentication and decrypt the entire vault, exposing all stored passwords in plaintext. This could lead to mass credential theft if an attacker gains access to a user's Windows session.

Technical details

The vulnerability is an insecure credential storage issue (CWE-522) in UpSignOn for Windows versions prior to 7.19.0. The biometric unlock key is stored in the Windows PasswordVault API without sufficient protection, allowing local attackers with standard user privileges to retrieve it from the same Windows session without triggering authentication. Once an attacker obtains the biometric key, they can decrypt the protected vault files and export the entire password manager contents in cleartext. The attack requires local network or physical access and an active Windows session but no administrative privileges. Version 7.19.0, released 05/08/2026, addresses this issue with security fixes.

Affected products

  • UpSignOn UpSignOn for Windows before 7.19.0

Timeline

  • 2026-09-02: disclosed
  • 2026-08-05: patched: Version 7.19.0 released with security fixes

References

Related threats