VORANT. Threat Intelligence Sign in Create a free account

Imprivata EAM key cannot be rotated

routine vulnerability healthcare

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Imprivata Enterprise Access Management has no way to rotate its RSA key, letting a stolen private key impersonate the appliance indefinitely.

CERT/CC published VU#273940 describing a design flaw in Imprivata Enterprise Access Management (EAM), an SSO/authentication platform widely used in clinical environments, affecting versions 26.2.6 and below. The appliance generates its X.509 identity certificate from a single RSA key pair with no supported mechanism to rotate it after deployment. Because Imprivata EAM brokers authentication for clinical workstations, EHR platforms, and shared-device workflows, an attacker who obtains the private key — via backup exfiltration, hypervisor snapshot theft, or privileged filesystem access — can impersonate the trusted appliance indefinitely, intercepting SSO tokens, session assertions, and credentials across every downstream system that trusts it. If forward secrecy is not enforced on upstream connections, previously captured traffic could also be decrypted retroactively.

There is no CVE exploitation reported in the wild; this is a disclosed design weakness (CVE-2026-82356) rather than an active campaign. Imprivata did not respond to CERT/CC's coordination attempts but is reportedly aware and tracking the issue internally, with no fix or timeline published. Because the underlying key cannot be replaced short of a full appliance redeployment, any compromise of the key has an unusually long tail of exposure compared to typical certificate-based flaws.

Defenders running Imprivata EAM should treat the appliance's private key and any backups/snapshots containing it as high-value assets: restrict filesystem and administrative access tightly, secure and encrypt backups and hypervisor snapshots, and enforce perfect forward secrecy on all upstream TLS connections to limit retroactive decryption risk if the key is ever exposed. Monitor for unexpected certificate reuse or duplicate appliance identities on the network as a possible indicator of impersonation, and prepare a redeployment plan since that is currently the only remediation path.

Mentioned in this report

Vulnerabilities CVE-2026-82356

Source reporting: https://kb.cert.org/vuls/id/273940

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 9,539 reports from 155 sources, 1,375 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs