Skip to main content

CISA issues update for Imprivata EAM RSA key rotation flaw

49th article in the last 90 days, one of 610 articles referencing Cybersecurity and Infrastructure Security Agency (CISA). Previous coverage: Netskope Outlines a Four-Step Approach to Securing Federal AI Use Cases (Sep 2026).

Companies mentioned

Best suited for

Seniority
Manager
Job function
Cybersecurity / Security Operations
Persona
Security Operations Leader
Buyer role
Decision Maker / Budget Holder
Buyer journey
Need to Buy
Adoption curve
Early Majority
Technology maturity
Market Correction
Industry
Health Care / Health Care Equipment & Services / Health Care Providers & Services / Health & Wellness

Our classification, not the publisher's statement. Best suited for, not only for.

Imprivata Enterprise Access Management (EAM) is affected by a cryptographic vulnerability in versions 26.2.6 and below. The issue involves the reuse of the same RSA key pair for generating the appliance identity certificate, which enables an attacker with the private key to impersonate the appliance to trusted endpoints.

The vulnerability is identified as CVE-2026-82356. Imprivata EAM uses an RSA key pair to generate an X.509 certificate used to identify the appliance to clinical workstations, Electronic Health Record (EHR) platforms, and shared-device workflows that rely on it for authentication. After reviewing product documentation and engaging Imprivata support, it was confirmed that there is no supported mechanism to rotate this RSA key pair after deployment.

If an attacker obtains the private key, such as through backup exfiltration, a hypervisor snapshot, or privileged access to the appliance filesystem, the attacker can impersonate the appliance to any endpoint that trusts its certificate. Because Imprivata EAM is in the authentication path, this can enable persistent and difficult-to-detect interception of authentication traffic across every application the appliance brokers, including SSO tokens, session assertions, and credentials for EHR and clinical systems. If perfect forward secrecy is not enforced, previously captured traffic can also be decrypted retroactively, and the access persists until the appliance is redeployed because the key pair cannot be rotated.

No fix or timeline was provided at the time of publication. The vendor was reported to be aware of the issue and tracking it internally, and working toward a resolution. Until a fix is available, the guidance described is to protect the appliance’s private key by restricting filesystem and administrative access, securing backups and hypervisor snapshots, and enforcing perfect forward secrecy on upstream connections to limit the impact of any key compromise.

Imprivata EAM provides no supported mechanism to rotate its RSA key pair after deployment, so the same key pair is used indefinitely to generate the appliance’s X.509 certificate. The guidance also notes that there is no supported means to revoke or replace the key and that doing so short of redeploying the product is not available.

Blog post, originally published by Alexander Curtis at kb.cert.org.