Impact
The vulnerability enables an attacker to manipulate a valid SAML Identity Provider (IdP) response under specific conditions, allowing them to impersonate another Secret Server user. By presenting a crafted SAML assertion that the server accepts, the attacker bypasses normal authentication controls and gains the impersonated user’s level of access. This flaw is classified as CWE-290, Authentication Bypass by Certificate or Privilege Abuse.
Affected Systems
Delinea Secret Server (On‑Prem) is the affected product. No explicit vulnerable version range is listed, but the vendor’s advisory recommends upgrading to Secret Server version 12.2.7 or newer to resolve the issue.
Risk and Exploitability
The CVSS score of 9.5 marks the issue as critical, while the EPSS score of less than 1 % suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the target environment to use SAML for authentication and depends on specific IdP response conditions described by the vendor. An attacker would need a valid SAML assertion that satisfies these conditions, which limits the attack surface and contributes to the low EPSS score.
OpenCVE Enrichment