CVE-2026-92680: Araxis Merge insufficiently protected credentials
Published Sep 24, 2026
·Updated
Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.
Affected Software
1 affected component
Araxis Merge for Windows>=2011.4074<=2026.0
Event History
Sep 24, 2026
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be authenticated on the Windows system and have non-administrative access. The attacker can retrieve credentials stored by the target user in Araxis Merge.
2
What credentials are at risk?
User-configured credentials for remote servers that the target user has stored in Araxis Merge are affected. The issue allows those stored credentials to be retrieved and unencrypted.
3
Which versions are affected?
Araxis Merge for Windows versions 2011.4074 through 2026.0 are affected.