CVE Feed

    Dashboard / CVE / CVE-2023-36266

    CVE-2023-36266

    An issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Browser Extensions version 16.5.4 (fixed in 17.2), allows local attackers to gain sensitive information via plaintext password storage in memory after the user is already logged in, and may persist after logout. NOTE: the vendor disputes this for two reasons: the information is inherently available during a logged-in session when the attacker can read from arbitrary memory locations, and information only remains available after logout because of memory-management limitations of web browsers (not because the Keeper technology itself is retaining the information).

    Published:Jul 12, 2023
    Last Modified:Jun 9, 2025
    EPS:Jul 12, 2023
    EPSS Score:0.00329
    CVSS Score:5.5

    Affected Products

    Vendor
    Keepersecurity
    Product
    Keeper
    Vendor
    Keepersecurity
    Product
    Keeperfill

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High