CVE-2026-19117 PUBLISHED

Delinea Secret Server FIDO2 credential registration authentication bypass vulnerability

Assigner: Delinea
Reserved: 06.08.2026 Published: 02.09.2026 Updated: 02.09.2026

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Delinea
Product Secret Server (On-Prem)
Versions Default: unaffected
  • affected from 10.6.0 to 11.7.61 (incl.)
  • affected from 11.8.0 to 11.8.1 (incl.)
  • affected from 11.9.0 to 11.9.47 (incl.)
  • affected from 12.0.0 to 12.0.22 (incl.)
  • affected from 12.1.0 to 12.1.2 (incl.)

Solutions

Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.

Customers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability

References

Problem Types

  • CWE-290 Authentication bypass by spoofing CWE

Impacts

  • CAPEC-115 Authentication Bypass