CVE-2026-15640 PUBLISHED

Authentication Bypass via SAML Response Manipulation

Assigner: Delinea
Reserved: 13.07.2026 Published: 15.09.2026 Updated: 16.09.2026

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H
CVSS Score: 9.5

Product Status

Vendor Delinea
Product Secret Server (On-Prem)
Versions Default: unaffected
  • affected from 10.5.0 to 12.1.3 (incl.)

Solutions

Upgrade to secret server version 12.2.7 or later

Credits

  • Aidan Stansfield - Division 5 finder

References

Problem Types

  • CWE-290 Authentication bypass by spoofing CWE

Impacts

  • CAPEC-115 Authentication Bypass