GHSA-hfv3-23j2-3cp6MediumCVSS 5.5
Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for...
🔗 CVE IDs covered (1)
📋 Description
Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-92680
- https://github.com/grepstrength/CVE-2026-92680
- https://grepstrength.com/research/araxis-merge
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-267-01.json
- https://www.araxis.com/merge/release-notes-2026#Merge-SA-26-00
- https://www.cve.org/CVERecord?id=CVE-2026-92680
- https://github.com/advisories/GHSA-hfv3-23j2-3cp6