Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to secret server version 12.2.7 or later
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://delinea.com/security-advisories |
|
History
Tue, 15 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user. | |
| Title | Authentication Bypass via SAML Response Manipulation | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Delinea
Published:
Updated: 2026-09-15T23:22:15.196Z
Reserved: 2026-07-13T18:18:24.315Z
Link: CVE-2026-15640
No data.
Status : Received
Published: 2026-09-16T00:17:03.577
Modified: 2026-09-16T00:17:03.577
Link: CVE-2026-15640
No data.
OpenCVE Enrichment
No data.
Weaknesses