Padding Oracle Vulnerability in Delinea Secret Server
CVE-2026-15638
9.1CRITICAL
What is CVE-2026-15638?
This vulnerability allows an unauthenticated user with access to Delinea Secret Server to exploit a padding oracle technique, enabling them to decrypt or encrypt sensitive data using the server's cryptographic keys. Although the key remains protected, this issue poses a significant risk to data confidentiality, as it allows malicious actors to manipulate and potentially access sensitive information.
Affected Version(s)
Secret Server (On-Prem) Windows 10.5.1 <= 12.1.3
