Secret Server

Delinea · 11 CVEs

CVE-2025-12810
MEDIUM

Failure in Password Rotation and Check-in Mechanism in Secret Server Allows Reuse of Credentials

Jan 27, 2026

CVE-2025-6942
LOW

The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited dur…

Jul 2, 2025

CVE-2025-6943
MEDIUM

Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrato…

Jul 2, 2025

CVE-2024-12908
HIGH

Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within the proto…

Dec 26, 2024

CVE-2024-33891
HIGH

Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/web…

Apr 28, 2024

CVE-2024-25653
MEDIUM

Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unl…

Mar 14, 2024

CVE-2024-25652
HIGH

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with acces…

Mar 14, 2024

CVE-2024-25651
MEDIUM

User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attac…

Mar 14, 2024

CVE-2024-25650
MEDIUM

Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrato…

Mar 14, 2024

CVE-2024-25649
MEDIUM

In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machi…

Mar 14, 2024

CVE-2023-4589
CRITICAL

Insufficient verification of data authenticity vulnerability in Delinea Secret Server

Sep 6, 2023

CVE-2023-4588
MEDIUM

File accessibility vulnerability in Delinea Secret Server

Sep 6, 2023

Showing 1 to 11 of 11 CVEs