Back to vendor advisories
Delinea Security AdvisoriesCVE-2026-19117

Delinea Secret Server on-prem FIDO2 credential registration authentication bypass vulnerability - CVE-2026-19117

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

9.8CVSS out of 10Critical severity
Scope

What the vendor says is affected

  • Delinea Secret Server on-prem 10.6.0 through 11.7.61 11.8.0 through 11.8.1 11.9.0 through 11.9.47 12.0.0 through 12.0.22 12.1.0 through 12.1.2 Resolution:Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.Customers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability

Versions the vendor lists as fixed

  • Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.Customers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability
Next step

What the vendor recommends

Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.Customers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability

Review the complete instructions on the vendor's site
Update history

What changed in later vendor updates

SecurityAlert records field-level changes from the point we begin following a bulletin. Earlier vendor changes may not have a field-by-field record.

    • The vendor changed the advisory title.
    • The vendor changed the advisory summary.
    • The vendor changed the advisory ID.
    • Severity changed from Low to Critical.
    • CVSS changed from 3.8 to 9.8.
    • Added CVEs: CVE-2026-19117.
    • Removed CVEs: CVE-2025-6942.
    • Added affected products: Delinea Secret Server on-prem 10.6.0 through 11.7.61 11.8.0 through 11.8.1 11.9.0 through 11.9.47 12.0.0 through 12.0.22 12.1.0 through 12.1.2 Resolution:Upgrade to secret server version 12.2.7 or later, or upgrade to....
    • Removed affected products: Delinea Secret Server on-prem version 11.7.49 and earlier ResolutionUpgrade to Secret Server version 11.7.60 or later.
    • Added fixed versions: Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.Customers on versions prior to 11.7 should upgrade to a supported version to....
    • Removed fixed versions: Upgrade to Secret Server version 11.7.60 or later.
    • The vendor changed its remediation guidance.
    • Added affected products: Delinea Secret Server on-prem version 11.7.49 and earlier ResolutionUpgrade to Secret Server version 11.7.60 or later.
    • Removed affected products: Delinea Secret Server on-prem version 11.7.49 and earlier ResolutionUpgrade to Secret Server version 11.7.60 or later CVE Details CVE ID: CVE-2025-6942 Published Date: July 2, 2025 Vulnerability Type: Authorization....
    • Added fixed versions: Upgrade to Secret Server version 11.7.60 or later.
    • Removed fixed versions: Upgrade to Secret Server version 11.7.60 or later CVE Details CVE ID: CVE-2025-6942 Published Date: July 2, 2025 Vulnerability Type: Authorization Bypass Through User-Controlled Key CWE: 639 CVSS v3 Score: 3.8 CVSS v3....
    • The vendor changed its remediation guidance.
Timeline

When this advisory changed

  1. Added to SecurityAlert

    We collected the advisory from the official source.

  2. Published by Delinea

    The publication date reported by the vendor.

  3. Confirmed at the source

    Our collector saw this advisory during a later source check.

Vulnerabilities

CVEs named in this advisory