CVE-2026-15639 PUBLISHED

Reflected Cross-Site Scripting

Assigner: Delinea
Reserved: 13.07.2026 Published: 15.09.2026 Updated: 16.09.2026

An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H
CVSS Score: 9.3

Product Status

Vendor Delinea
Product Secret Server (On-Prem)
Versions Default: unaffected
  • affected from 10.2.19 to 11.9.48 (incl.)

Solutions

Upgrade to secret server version 12.0.20 or later.

Credits

  • Aidan Stansfield - Division 5 finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE

Impacts

  • CAPEC-591 Reflected XSS