Vulnerabilities & PatchesEmerging1 src
VU#273940: Enterprise Access Management EAM does not rotate RSA keys
Overview
Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26. 2. 6 and below. The product provides no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X. 509 certificate.
Description
CVE-2026-82356
Imprivata EAM uses an RSA key pair to generate the X. 509 certificate that identifies the appliance to the clinical workstations, Electronic Health Record (EHR) platforms, and shared-device workflows that rely on it for authentication. After reviewing the product documentation and engaging Imprivata support, it was confirmed that no supported mechanism exists to rotate this RSA key pair after deployment.