Improper Authentication in Delinea Inc. Secret Server Affects Multiple Versions
CVE-2025-12810
What is CVE-2025-12810?
An improper authentication vulnerability exists in Delinea Inc. Secret Server On-Prem, specifically within the RPC Password Rotation modules. This issue occurs when a secret configured with 'change password on check in' enabled continues to be checked in even after a password change fails, following the retry limit. This results in the secret being left in an inconsistent state with an incorrect password, potentially compromising security protocols. To mitigate the risk, users are advised to upgrade to version 11.9.47 or later, ensuring the secret remains checked out if the password change is unsuccessful.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Secret Server On-Prem 11.8.1
Secret Server On-Prem 11.9.6
Secret Server On-Prem 11.9.25
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
