VU#273940: Enterprise Access Management EAM does not rotate RSA keys
Imprivata EAM 26.2.6 and earlier cannot rotate its RSA key, enabling persistent impersonation after key theft.
CERT/CC published VU#273940 for CVE-2026-82356 in Imprivata Enterprise Access Management versions 26.2.6 and below. The clinical and enterprise SSO platform has no supported way to rotate the RSA key pair used to generate its X.509 appliance certificate, so the same key is used indefinitely. An attacker who obtains the private key through backup exfiltration, a hypervisor snapshot, or filesystem access can impersonate the appliance and intercept SSO tokens, session assertions, and EHR credentials until the product is redeployed. Imprivata is tracking the issue internally, but no fix or timeline has been provided; CERT/CC advises restricting key access and enforcing perfect forward secrecy.
- CVE-2026-82356 affects Imprivata EAM 26.2.6 and earlier.
- No supported mechanism exists to rotate the appliance RSA key pair.
- A stolen private key allows persistent impersonation of the appliance.
- Compromise could expose SSO tokens and EHR credentials.
- Imprivata has published no fix or remediation timeline.
Vulnerabilities mentionedAll →
- CVE-2026-823567.5—Non-rotatable RSA Key Pair in Imprivata Enterprise Access Management (EAM) <=26.2.6published · Imprivata Enterprise Access Management (EAM)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82356 | Non-rotatable RSA Key Pair in Imprivata Enterprise Access Management (EAM) <=26.2.6 Imprivata Enterprise Access Management (EAM) versions 26.2.6 and earlier generate an X.509 certificate from an RSA key pair that cannot be rotated after deployment, so the same long-lived key is used indefinitely. This is a key-management weakness rather than a flaw an attacker triggers directly: the impact materializes if the private key is ever compromised through a separate intrusion, side-channel, or future cryptanalytic advance. An attacker who obtains the key can forge or spoof the certificate indefinitely, enabling impersonation of the EAM service or man-in-the-middle interception of sessions that trust it, with no clean rotation path to invalidate the stolen key. Affected parties are organizations running Imprivata EAM 26.2.6 or older, which Imprivata deploys primarily in healthcare settings such as hospitals and health systems. There is no CVSS score yet, no public proof of concept, and no known exploitation in the wild. |
Full article412 words · extracted from kb.cert.org · click to collapse
Overview
Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X.509 certificate.
Description
CVE-2026-82356
Imprivata EAM uses an RSA key pair to generate the X.509 certificate that identifies the appliance to the clinical workstations, Electronic Health Record (EHR) platforms, and shared-device workflows that rely on it for authentication. After reviewing the product documentation and engaging Imprivata support, it was confirmed that no supported mechanism exists to rotate this RSA key pair after deployment.
Using a single RSA key pair indefinitely for certificate generation violates cryptographic best practices. Because the key cannot be rotated, an attacker who obtains the private key retains a valid, trusted appliance identity for as long as the deployment remains in service, with no supported means to revoke or replace it short of redeploying the product.
Impact
An attacker who obtains the private key, for example through backup exfiltration, a hypervisor snapshot, or privileged access to the appliance filesystem, can impersonate the appliance to any endpoint that trusts its certificate. Because Imprivata EAM sits directly in the authentication path, this allows persistent, difficult-to-detect interception of authentication traffic across every application the appliance brokers, including SSO tokens, session assertions, and credentials for EHR and clinical systems. If perfect forward secrecy is not enforced, previously captured traffic can also be decrypted retroactively. Because the key pair cannot be rotated, this access persists until the appliance is redeployed.
Solution
Unfortunately, Imprivata could not be reached to coordinate this case. The vendor is aware of the issue, which they are tracking internally, and is reported to be working toward a resolution. No fix or timeline has been provided at the time of publication.
Until a fix is available, affected users should protect the appliance's private key by restricting filesystem and administrative access, securing backups and hypervisor snapshots, and enforcing perfect forward secrecy on upstream connections to limit the impact of any key compromise.
Acknowledgements
Thank you to Frank "5y5tem5" Mileto for reporting this issue. This document was written by Alexander Curtis.
Vendor Information
273940
Filter by status:
Filter by content: Additional information available
Sort by:
Other Information
| CVE IDs: | CVE-2026-82356 |
| API URL: | VINCE JSON | CSAF |
| Date Public: | 2026-09-23 |
| Date First Published: | 2026-09-23 |
| Date Last Updated: | 2026-09-23 18:22 UTC |
| Document Revision: | 1 |