CVE-2026-92680
Araxis Merge insufficiently protected credentials
CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th
Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.
| CWE | CWE-522 |
| Vendor | araxis |
| Product | merge |
| Published | Sep 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for araxis merge
Be the first to know when new medium vulnerabilities affecting araxis merge are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Araxis / Merge
2011.4074 < 2026.1
References
araxis.com: https://www.araxis.com/merge/release-notes-2026#Merge-SA-26-00 grepstrength.com: https://grepstrength.com/research/araxis-merge cve.org: https://www.cve.org/CVERecord?id=CVE-2026-92680 raw.githubusercontent.com: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-267-01.json github.com: https://github.com/grepstrength/CVE-2026-92680
Credits
Kelvin Winborne (grepStrength), grepStrength Security LLC