Description
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
Published: 2026-09-15
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability enables an attacker to manipulate a valid SAML Identity Provider (IdP) response under specific conditions, allowing them to impersonate another Secret Server user. By presenting a crafted SAML assertion that the server accepts, the attacker bypasses normal authentication controls and gains the impersonated user’s level of access. This flaw is classified as CWE-290, Authentication Bypass by Certificate or Privilege Abuse.

Affected Systems

Delinea Secret Server (On‑Prem) is the affected product. No explicit vulnerable version range is listed, but the vendor’s advisory recommends upgrading to Secret Server version 12.2.7 or newer to resolve the issue.

Risk and Exploitability

The CVSS score of 9.5 marks the issue as critical, while the EPSS score of less than 1 % suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the target environment to use SAML for authentication and depends on specific IdP response conditions described by the vendor. An attacker would need a valid SAML assertion that satisfies these conditions, which limits the attack surface and contributes to the low EPSS score.

Generated by OpenCVE AI on September 18, 2026 at 13:20 UTC.

Remediation

Vendor Solution

Upgrade to secret server version 12.2.7 or later


OpenCVE Recommended Actions

  • Update Delinea Secret Server to version 12.2.7 or later
  • Ensure that SAML IdP responses are signed and validated by the server
  • Restrict SAML authentication to trusted IdPs and monitor for anomalous authentication attempts

Generated by OpenCVE AI on September 18, 2026 at 13:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
Title Authentication Bypass via SAML Response Manipulation
Weaknesses CWE-290
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Delinea

Published:

Updated: 2026-09-16T19:37:42.603Z

Reserved: 2026-07-13T18:18:24.315Z

Link: CVE-2026-15640

cve-icon Vulnrichment

Updated: 2026-09-16T19:37:38.782Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T00:17:03.577

Modified: 2026-09-18T19:34:36.657

Link: CVE-2026-15640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T13:30:09Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing