Skip to content

Build1 publisher2 min readPublished

Delinea's 2 September hotfixes all land inside the new SAML impersonation range

Delinea scored CVE-2026-15640 at 9.5 on CVSS v4 for on-prem Secret Server 10.5.0 through 12.1.3, and 12.2.7 is the only listed build that also clears the padding oracle and the FIDO2 registration bug.

The Engineer · Build desk

Illustration accompanying Delinea's 2 September hotfixes all land inside the new SAML impersonation range

What happened

  • Delinea says a valid SAML IdP response can, under certain conditions, be used to impersonate another Secret Server user on on-prem versions 10.5.0 through 12.1.3, with 12.2.7 or later as the fix.
  • A second entry dated the same day, CVE-2026-15638, is a padding oracle an unauthenticated user can drive to encrypt or decrypt data with one of the server's keys, scored 9.1, with the key itself not exposed.
  • The third 15 September entry, CVE-2026-15639, is a 9.3 cross-site scripting bug that needs a legitimate user to open the attacker's link, and it is fixed in 12.0.20.
  • Two weeks earlier Delinea published CVE-2026-19117, a FIDO2 credential registration bypass scored 9.8 under CVSS v3, offering hotfixes at 12.1.3, 12.0.23, 11.9.48, 11.8.2 and 11.7.62.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision Teams that took the hotfix path in early September have to open the change ticket again: 12.1.3 was the remedy on 2 September and the top of an affected range on 15 September.
  • constraint For anything older than 11.7 the vendor's remedy is to move to a supported version first.
  • capability One upgrade to 12.2.7 retires every on-prem Secret Server advisory on the page. The alternative is four separate patch windows.
  • exposure Until that upgrade lands, an unauthenticated party who can reach the vault over the network can use it to encrypt and decrypt data with one of its own keys.

On 2 September Delinea listed five hotfix builds for the FIDO2 credential registration bug: 12.1.3, 12.0.23, 11.9.48, 11.8.2 and 11.7.62 [7]. CVE-2026-15640 affects on-prem Secret Server 10.5.0 through 12.1.3 [1]. All five of those builds sit at or below that ceiling, so none of them is outside the SAML range [9]. The two advisories carry publication dates thirteen days apart [15].

The padding oracle published on the later date, CVE-2026-15638, covers 10.5.1 through 12.1.3 and resolves in the same build, 12.2.7 [5]. The cross-site scripting issue, CVE-2026-15639, affects 10.2.19 through 11.9.48 and resolves in 12.0.20 [4]. Version 12.2.7 is above the top of all four on-prem ranges on the page, so a single upgrade takes an installation out of every one of them [10].

Delinea published the vector as well as the score: AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H [3]. On the exploitability metrics only AC:H and AT:P are below their worst values, so the advisory has the attack arriving over the network with no privileges and no user interaction [11]. Confidentiality, integrity and availability are all High for subsequent systems, while the vulnerable system's own availability impact is None [12].

A base score is a claim about a reference deployment. For 9.5 to describe yours, the Secret Server front end has to be reachable from wherever an attacker sits, and the SAML login path has to be in use. The subsequent-system metrics assume that impersonating a vault user buys access to something else. Delinea's advisory says the impersonation happens under certain conditions and does not describe them [16].

The FIDO2 bug carries the bigger number, 9.8, scored under CVSS v3 [6]. The three advisories dated 15 September are scored under v4 [3]. Different formulas and different metric sets produced those two figures, so ordering a v3 9.8 against a v4 9.5 does not tell you which to patch first [13].

Both authentication bypasses land in the same class. Delinea filed CVE-2026-15640 and CVE-2026-19117 under CWE-290, authentication bypass by spoofing, and both sit in the federated and hardware-token login paths [18]. All four Secret Server entries name the on-prem product, and the FIDO2 entry adds that it affects on-premises deployments only [17][6]. The Cloud Suite items on the same page run on their own track, including CVE-2026-2409, an SQL injection allowing argument injection, scored 9.3 under CVSS v4, fixed in 25.2 HF1 and credited to reporters Jess Parker and Radu Enachi [14].

What to watch

  • Whether Delinea backports the SAML fix into an 11.x, 12.0 or 12.1 hotfix for sites that cannot jump to 12.2.7.
  • Whether Delinea publishes the conditions under which the SAML IdP response can be replayed, and any detection guidance.
  • Whether CVE-2026-15640 or CVE-2026-15638 appears in exploitation reporting. Reporting would move the upgrade from planned to emergency.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories