Description
An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.
Published: 2026-09-15
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side JavaScript execution via reflected XSS
Action: Patch immediately
AI Analysis

Impact

An attacker can construct a malicious link that, when clicked by an authenticated user, causes the victim’s browser to execute attacker‑supplied JavaScript. The injected code runs with the user’s credentials, enabling session theft, credential phishing, or other malicious actions within the Secret Server application.

Affected Systems

Delinea Secret Server On‑Prem, versions prior to 12.0.20. No other vendors or products are affected.

Risk and Exploitability

The CVSS score of 9.3 classifies this flaw as critical, yet the EPSS score of less than 1% indicates a very low probability of public exploitation at present. It is not yet listed in CISA’s KEV catalog. Exploitation requires user interaction—the user must click the crafted link, typically delivered via phishing or other social‑engineering techniques. Once activated, the victim’s browser runs the injected code without additional privileges.

Generated by OpenCVE AI on September 18, 2026 at 11:33 UTC.

Remediation

Vendor Solution

Upgrade to secret server version 12.0.20 or later.


OpenCVE Recommended Actions

  • Upgrade Delinea Secret Server to version 12.0.20 or later, as released by the vendor.
  • Restrict access to the Secret Server instance so that only trusted internal users can reach it, minimizing the likelihood that a malicious link reaches a legitimate user.
  • Deploy a web‑application firewall or input‑validation rule to reject URLs containing script payloads in query parameters until the patch can be applied.

Generated by OpenCVE AI on September 18, 2026 at 11:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.
Title Reflected Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Delinea

Published:

Updated: 2026-09-16T19:37:19.729Z

Reserved: 2026-07-13T18:18:22.770Z

Link: CVE-2026-15639

cve-icon Vulnrichment

Updated: 2026-09-16T19:37:16.215Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T00:17:03.453

Modified: 2026-09-18T19:34:36.657

Link: CVE-2026-15639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T11:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')