Description
An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to secret server version 12.0.20 or later.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://delinea.com/security-advisories |
|
History
Tue, 15 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker. | |
| Title | Reflected Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Delinea
Published:
Updated: 2026-09-15T23:21:38.473Z
Reserved: 2026-07-13T18:18:22.770Z
Link: CVE-2026-15639
No data.
Status : Received
Published: 2026-09-16T00:17:03.453
Modified: 2026-09-16T00:17:03.453
Link: CVE-2026-15639
No data.
OpenCVE Enrichment
No data.
Weaknesses