Secret Server
Delinea · 11 CVEs
Failure in Password Rotation and Check-in Mechanism in Secret Server Allows Reuse of Credentials
Jan 27, 2026
The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited dur…
Jul 2, 2025
Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrato…
Jul 2, 2025
Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within the proto…
Dec 26, 2024
Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/web…
Apr 28, 2024
Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unl…
Mar 14, 2024
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with acces…
Mar 14, 2024
User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attac…
Mar 14, 2024
Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrato…
Mar 14, 2024
In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machi…
Mar 14, 2024
Insufficient verification of data authenticity vulnerability in Delinea Secret Server
Sep 6, 2023
File accessibility vulnerability in Delinea Secret Server
Sep 6, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-12810 | Failure in Password Rotation and Check-in Mechanism in Secret Server Allows Reuse of Credentials | MEDIUM | 0.45% | Jan 27, 2026 |
| CVE-2025-6942 | The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited during an initial authorization event that… | LOW | 0.15% | Jul 2, 2025 |
| CVE-2025-6943 | Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables. | MEDIUM | 0.16% | Jul 2, 2025 |
| CVE-2024-12908 | Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within the protocol handler function, URI's were compare… | HIGH | 0.71% | Dec 26, 2024 |
| CVE-2024-33891 | Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService.asmx. This is rela… | HIGH | 1.05% | Apr 28, 2024 |
| CVE-2024-25653 | Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is enabled, to view sy… | MEDIUM | 0.40% | Mar 14, 2024 |
| CVE-2024-25652 | In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED… | HIGH | 0.59% | Mar 14, 2024 |
| CVE-2024-25651 | User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user is valid… | MEDIUM | 0.48% | Mar 14, 2024 |
| CVE-2024-25650 | Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmetric Key (used to e… | MEDIUM | 0.25% | Mar 14, 2024 |
| CVE-2024-25649 | In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a me… | MEDIUM | 0.08% | Mar 14, 2024 |
| CVE-2023-4589 | Insufficient verification of data authenticity vulnerability in Delinea Secret Server | CRITICAL | 0.32% | Sep 6, 2023 |
| CVE-2023-4588 | File accessibility vulnerability in Delinea Secret Server | MEDIUM | 0.34% | Sep 6, 2023 |
Showing 1 to 11 of 11 CVEs