Authentication Bypass via SAML Response Manipulation - CVE-2026-15640
CVE-2026-15640
Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules). This issue affects Secret Server On-Prem: 11.8.1, 11.9.6, 11.9.25.
Upgrade to Secret Server version 11.9.47 or later The secret will remain checked out when the password change fails.
Review the complete instructions on the vendor's siteThe publication date reported by the vendor.
We collected the advisory from the official source.
Our collector saw this advisory during a later source check.