Loading market data...
← Back to CVE feed

CVE-2026-92680

MEDIUM CVSS 5.5 View on NVD ↗

Description

Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Published: Sep 24, 2026 16:17 UTC Modified: Sep 24, 2026 19:37 UTC