๐Ÿ” CVE Alert

CVE-2026-15640

UNKNOWN 0.0

Authentication Bypass via SAML Response Manipulation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

CWE CWE-290
Vendor delinea
Product secret server (on-prem)
Published Sep 15, 2026
Last Updated Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for delinea secret server (on-prem)

Be the first to know when new unknown vulnerabilities affecting delinea secret server (on-prem) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Delinea / Secret Server (On-Prem)
10.5.0 โ‰ค 12.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
delinea.com: https://delinea.com/security-advisories

Credits

Aidan Stansfield - Division 5