{"id":"CVE-2026-92680","published":"2026-09-24T16:17:14.357","lastModified":"2026-09-26T23:16:39.217","description":"Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.","cvssScore":5.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-522"],"vendors":[],"products":[],"references":[{"url":"https://github.com/grepstrength/CVE-2026-92680","tags":[]},{"url":"https://grepstrength.com/research/araxis-merge","tags":[]},{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-267-01.json","tags":[]},{"url":"https://www.araxis.com/merge/release-notes-2026#Merge-SA-26-00","tags":[]},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-92680","tags":[]}],"exploitRefs":[{"url":"https://github.com/grepstrength/CVE-2026-92680","tags":[]}],"hasPoc":true,"ai":null}