Improper Authentication in Delinea Inc. Secret Server Affects Multiple Versions
CVE-2025-12810
5.3MEDIUM
What is CVE-2025-12810?
An improper authentication vulnerability exists in Delinea Inc. Secret Server On-Prem, specifically within the RPC Password Rotation modules. This issue occurs when a secret configured with 'change password on check in' enabled continues to be checked in even after a password change fails, following the retry limit. This results in the secret being left in an inconsistent state with an incorrect password, potentially compromising security protocols. To mitigate the risk, users are advised to upgrade to version 11.9.47 or later, ensuring the secret remains checked out if the password change is unsuccessful.
Affected Version(s)
Secret Server On-Prem 11.8.1
Secret Server On-Prem 11.9.6
Secret Server On-Prem 11.9.25
