CVE-2026-15640
Authentication Bypass via SAML Response Manipulation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
| CWE | CWE-290 |
| Vendor | delinea |
| Product | secret server (on-prem) |
| Published | Sep 15, 2026 |
| Last Updated | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for delinea secret server (on-prem)
Be the first to know when new unknown vulnerabilities affecting delinea secret server (on-prem) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Delinea / Secret Server (On-Prem)
10.5.0 โค 12.1.3
Credits
Aidan Stansfield - Division 5