Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as
that user. This issue affects on-premises deployments only.

Project Subscriptions

Vendors Products
Delinea Subscribe
Secret Server Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62. Customers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability


Workaround

No workaround given by the vendor.

References
History

Thu, 03 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Delinea
Delinea secret Server
Vendors & Products Delinea
Delinea secret Server

Wed, 02 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.
Title Delinea Secret Server FIDO2 credential registration authentication bypass vulnerability
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Delinea

Published:

Updated: 2026-09-02T18:32:08.651Z

Reserved: 2026-08-06T14:39:05.258Z

Link: CVE-2026-19117

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-02T19:17:16.490

Modified: 2026-09-03T16:41:09.297

Link: CVE-2026-19117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:30:05Z

Weaknesses