CVE-2026-15640
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.5
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H
- EPSS probability
- 0.28%
- CWE
- CWE-290
- Published
- 2026-09-15
- Last modified
- 2026-09-16
Affected products
- Delinea Secret Server (On-Prem)
Weakness type
Related vulnerabilities
- CVE-2026-25938 — FUXA Unauthenticated Remote Code Execution in Node-RED Integration
- CVE-2026-27478 — Unity Catalog has a JWT Issuer Validation Bypass Allows Complete User Impersonation
- CVE-2025-11250 — Authentication Bypass
- CVE-2026-33654 — Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling
- CVE-2026-31889 — Shopware has a potential take over of app credentials
- CVE-2026-33661 — WeChat Pay callback signature verification bypassed when Host header is localhost
- CVE-2026-76423 — Cisco ISE API Authentication Bypass Vulnerability
- CVE-2026-6213 — Remote Spark SparkView RCE