Delinea Secret Server

4 known vulnerabilities in Delinea Secret Server, 4 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-15640 CVSS 9.5 critical Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
  • CVE-2026-15639 CVSS 9.3 critical An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the…
  • CVE-2026-15638 CVSS 9.1 critical An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's…
  • CVE-2026-19117 CVSS 9.8 critical Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate…