Severity: HighAction: Review
Vulnerability record
CVE-2026-82356
Severity: HighExploitation: No known exploitation
Patch status
No official fix confirmed yet
Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.
Description
Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate. Using an RSA key pair indefinitely for certificate generation is against best practices.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Intelligence timeline
Developments from the last 30 days, newest first.
- CVSS scoredUpdate
CVE-2026-82356 scored CVSS 7.5
Basis: NIST National Vulnerability Database
- Disclosed
VU#273940: Enterprise Access Management EAM does not rotate RSA keys
Basis: CERT/CC Vulnerability Notes (CERT advisory)
