Description
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to secret server version 12.2.7 or later
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://delinea.com/security-advisories |
|
History
Tue, 15 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user. | |
| Title | Authentication Bypass via SAML Response Manipulation | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Delinea
Published:
Updated: 2026-09-15T23:22:15.196Z
Reserved: 2026-07-13T18:18:24.315Z
Link: CVE-2026-15640
No data.
Status : Received
Published: 2026-09-16T00:17:03.577
Modified: 2026-09-16T00:17:03.577
Link: CVE-2026-15640
No data.
OpenCVE Enrichment
No data.
Weaknesses