# Imprivata EAM key cannot be rotated

Published: 2026-09-23 · Severity: routine · Sectors: healthcare
Canonical: https://vorant.io/reports/7af7fe6b-8fd9-5b94-a887-10508862477a/imprivata-eam-key-cannot-be-rotated

> Imprivata Enterprise Access Management has no way to rotate its RSA key, letting a stolen private key impersonate the appliance indefinitely.

CERT/CC published VU#273940 describing a design flaw in Imprivata Enterprise Access Management (EAM), an SSO/authentication platform widely used in clinical environments, affecting versions 26.2.6 and below. The appliance generates its X.509 identity certificate from a single RSA key pair with no supported mechanism to rotate it after deployment. Because Imprivata EAM brokers authentication for clinical workstations, EHR platforms, and shared-device workflows, an attacker who obtains the private key — via backup exfiltration, hypervisor snapshot theft, or privileged filesystem access — can impersonate the trusted appliance indefinitely, intercepting SSO tokens, session assertions, and credentials across every downstream system that trusts it. If forward secrecy is not enforced on upstream connections, previously captured traffic could also be decrypted retroactively.

There is no CVE exploitation reported in the wild; this is a disclosed design weakness (CVE-2026-82356) rather than an active campaign. Imprivata did not respond to CERT/CC's coordination attempts but is reportedly aware and tracking the issue internally, with no fix or timeline published. Because the underlying key cannot be replaced short of a full appliance redeployment, any compromise of the key has an unusually long tail of exposure compared to typical certificate-based flaws.

Defenders running Imprivata EAM should treat the appliance's private key and any backups/snapshots containing it as high-value assets: restrict filesystem and administrative access tightly, secure and encrypt backups and hypervisor snapshots, and enforce perfect forward secrecy on all upstream TLS connections to limit retroactive decryption risk if the key is ever exposed. Monitor for unexpected certificate reuse or duplicate appliance identities on the network as a possible indicator of impersonation, and prepare a redeployment plan since that is currently the only remediation path.

## Mentioned in this report

- Vulnerabilities: CVE-2026-82356

Source reporting: https://kb.cert.org/vuls/id/273940

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7af7fe6b-8fd9-5b94-a887-10508862477a/imprivata-eam-key-cannot-be-rotated.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
