Skip to content
Critical Vulnerabilities in Delinea Secret Server Expose Sensitive Credentials

Critical Vulnerabilities in Delinea Secret Server Expose Sensitive Credentials

First seen 16 Sep 2026, 19:58 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 19:54 UTC
  • Two critical vulnerabilities disclosed in Delinea Secret Server on September 15, 2026.
  • CVE-2026-15638 allows data manipulation; CVE-2026-15640 enables user impersonation.
  • Organizations must urgently patch to version 12.2.7 or later to mitigate risks.

On September 15, 2026, Delinea disclosed two unauthenticated critical vulnerabilities in Secret Server: CVE-2026-15638 (padding oracle, CVSS 9.1) and CVE-2026-15640 (SAML bypass, CVSS 9.5). These vulnerabilities affect versions 10.5.0 to 12.1.3 and can be exploited by unauthenticated attackers to manipulate sensitive data and impersonate users, including administrators. The vulnerabilities undermine the security of the privileged access management platform, which is crucial for managing SSH keys, API tokens, and other sensitive credentials. Delinea released fixes in version 12.2.000007 on August 28, 2026, and additional remediation in version 12.2.7. These issues are part of a broader cluster of four critical CVEs disclosed within two weeks, highlighting a significant risk for organizations relying on this platform.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-02
CVE-2026-19117 published
Delinea disclosed a FIDO2 credential registration bypass vulnerability, allowing unauthorized credential registration.
Forkast.News
2026-09-15
CVE-2026-15640 published
Delinea disclosed a SAML authentication bypass vulnerability allowing unauthenticated user impersonation.
Forkast.News
2026-09-15
CVE-2026-15638 published
Delinea disclosed a cryptographic padding oracle vulnerability that can be exploited by unauthenticated attackers.
Forkast.News
2026-09-15
CVE-2026-15639 published
Delinea disclosed a reflected cross-site scripting vulnerability affecting the same platform.
Forkast.News

More articles in this cluster (3)

Following this threat?

Track BankUnited and CVE-2026-15638 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed