CVE-2026-19117

9.8

Delinea · Secret Server (On-Prem)

A critical authentication bypass vulnerability allows unauthenticated attackers to register malicious FIDO2 credentials and gain unauthorized access to target accounts in Delinea Secret Server.

Executive summary

An unauthenticated attacker can achieve full account takeover in Delinea Secret Server (On-Prem) by registering unauthorized FIDO2 credentials, representing a critical security risk.

Vulnerability

This vulnerability is an authentication bypass (CWE-290) that allows an unauthenticated attacker to register their own FIDO2 credential against any target user account, effectively granting them legitimate access to that account.

Business impact

The ability for an unauthenticated attacker to bypass authentication mechanisms and compromise user accounts poses a severe risk to organizational security. Given the CVSS score of 9.8, this flaw could lead to complete system compromise, unauthorized data exfiltration, and the loss of administrative control over privileged credentials stored within Secret Server.

Remediation

Immediate Action: Upgrade to Secret Server version 12.2.7 or later, or apply the specific hotfix corresponding to your current version (12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62).

Proactive Monitoring: Review audit logs for suspicious credential registration activities or unexpected changes to multi-factor authentication configurations for user accounts.

Compensating Controls: Ensure the Secret Server instance is not exposed to the public internet and enforce strict network access controls to limit potential attack vectors until patching is completed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of this authentication bypass and the potential for full account takeover, organizations using Delinea Secret Server must prioritize patching immediately. Verify your current version and apply the recommended hotfixes or full version upgrades as specified by the vendor to eliminate the exposure window.

Sources