SAML Impersonation Vulnerability in Delinea Secret Server
CVE-2026-15640

9.5CRITICAL

Key Information:

Vendor

Delinea

Vendor
CVE Published:
15 September 2026

What is CVE-2026-15640?

This vulnerability allows an attacker to leverage a valid SAML IdP response to impersonate another user within Delinea Secret Server. If exploited, it could grant unauthorized access to sensitive information and functions, posing significant security risks to organizations that rely on effective identity management and security controls.

Affected Version(s)

Secret Server (On-Prem) Windows 10.5.0 <= 12.1.3

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.