Improper Authentication in Delinea Inc. Secret Server Affects Multiple Versions
CVE-2025-12810

5.3MEDIUM

Key Information:

Vendor
CVE Published:
27 January 2026

What is CVE-2025-12810?

An improper authentication vulnerability exists in Delinea Inc. Secret Server On-Prem, specifically within the RPC Password Rotation modules. This issue occurs when a secret configured with 'change password on check in' enabled continues to be checked in even after a password change fails, following the retry limit. This results in the secret being left in an inconsistent state with an incorrect password, potentially compromising security protocols. To mitigate the risk, users are advised to upgrade to version 11.9.47 or later, ensuring the secret remains checked out if the password change is unsuccessful.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Secret Server On-Prem 11.8.1

Secret Server On-Prem 11.9.6

Secret Server On-Prem 11.9.25

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.