Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.
Delinea Secret Server on-prem 10.6.0 through 11.7.61 11.8.0 through 11.8.1 11.9.0 through 11.9.47 12.0.0 through 12.0.22 12.1.0 through 12.1.2 Resolution:Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.Customers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability
Versions the vendor lists as fixed
Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.Customers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability
Next step
What the vendor recommends
Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.Customers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability
SecurityAlert records field-level changes from the point we begin following a bulletin. Earlier vendor changes may not have a field-by-field record.
The vendor changed the advisory title.
The vendor changed the advisory summary.
The vendor changed the advisory ID.
Severity changed from Low to Critical.
CVSS changed from 3.8 to 9.8.
Added CVEs: CVE-2026-19117.
Removed CVEs: CVE-2025-6942.
Added affected products: Delinea Secret Server on-prem 10.6.0 through 11.7.61 11.8.0 through 11.8.1 11.9.0 through 11.9.47 12.0.0 through 12.0.22 12.1.0 through 12.1.2 Resolution:Upgrade to secret server version 12.2.7 or later, or upgrade to....
Removed affected products: Delinea Secret Server on-prem version 11.7.49 and earlier ResolutionUpgrade to Secret Server version 11.7.60 or later.
Added fixed versions: Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.Customers on versions prior to 11.7 should upgrade to a supported version to....
Removed fixed versions: Upgrade to Secret Server version 11.7.60 or later.
The vendor changed its remediation guidance.
Added affected products: Delinea Secret Server on-prem version 11.7.49 and earlier ResolutionUpgrade to Secret Server version 11.7.60 or later.
Removed affected products: Delinea Secret Server on-prem version 11.7.49 and earlier ResolutionUpgrade to Secret Server version 11.7.60 or later CVE Details CVE ID: CVE-2025-6942 Published Date: July 2, 2025 Vulnerability Type: Authorization....
Added fixed versions: Upgrade to Secret Server version 11.7.60 or later.
Removed fixed versions: Upgrade to Secret Server version 11.7.60 or later CVE Details CVE ID: CVE-2025-6942 Published Date: July 2, 2025 Vulnerability Type: Authorization Bypass Through User-Controlled Key CWE: 639 CVSS v3 Score: 3.8 CVSS v3....
The vendor changed its remediation guidance.
Timeline
When this advisory changed
Added to SecurityAlert
We collected the advisory from the official source.
Published by Delinea
The publication date reported by the vendor.
Confirmed at the source
Our collector saw this advisory during a later source check.