Vulnerability record

CVE-2026-82356

Severity: HighExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate. Using an RSA key pair indefinitely for certificate generation is against best practices.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-82356 scored CVSS 7.5

    Basis: NIST National Vulnerability Database

  2. Disclosed

    VU#273940: Enterprise Access Management EAM does not rotate RSA keys

    Basis: CERT/CC Vulnerability Notes (CERT advisory)

Coverage

References