Impact
The vulnerability allows an attacker to register a synthetic FIDO2 credential under a target account when specific conditions are met. With this credential, the attacker can subsequently authenticate as that user, effectively bypassing normal authentication controls and enabling full access to the compromised account. The weakness is rooted in inadequate authorization controls that permit credential registration without proper verification.
Affected Systems
On‑premises deployments of Delinea Secret Server are impacted. All versions require updating to version 12.2.7 or later, or applying the designated hotfixes 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62. Organizations running versions prior to 11.7 are also affected and should move to a supported release.
Risk and Exploitability
Cloud‑based or local web access to the Secret Server portal constitutes the attack surface; the vulnerability is likely exploitable remotely through the registration interface. With a CVSS score of 9.8, the risk is severe, and the likelihood of exploitation remains high despite the absence of an EPSS score or KEV listing. If an attacker succeeds, they can impersonate legitimate users and gain full access to stored secrets.
OpenCVE Enrichment