← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 23, 2026 · 18:22via CERT/CC Vulnerability Notes

VU#273940: Enterprise Access Management EAM does not rotate RSA keys

Brief

Overview

Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.

  • 6 and below. The product provides no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X. 509 certificate.

Description

CVE-2026-82356

Imprivata EAM uses an RSA key pair to generate the X. 509 certificate that identifies the appliance to the clinical workstations, Electronic Health Record (EHR) platforms, and shared-device workflows that rely on it for authentication. After reviewing the product documentation and engaging Imprivata support, it was confirmed that no supported mechanism exists to rotate this RSA key pair after deployment.

Read more on CERT/CC Vulnerability Notes