Vendor advisories

Delinea Security Advisories

Browse 7 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 31 minutes ago Checked hourly

7 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Delinea Security AdvisoriesCVE-2026-19117
CriticalCVSS 9.8

Delinea Secret Server on-prem FIDO2 credential registration authentication bypass vulnerability - CVE-2026-19117

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

Affected productsDelinea Secret Server on-prem 10.6.0 through 11.7.61 11.8.0 through 11.8.1 11.9.0 through 11.9.47 12.0.0 through 12.0.22 12.1.0 through 12.1.2 Resolution:Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.Customers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability
Fixed versionsUpgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.Customers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability
Vendor guidance

Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.Customers on versions prior to 11.7 should upgrade to a supported version to ...

Delinea Security AdvisoriesCVE-2025-12811
MediumCVSS 6.9

Delinea Cloud Suite and Privileged Access Service - HTTP Request Smuggling vulnerability - CVE-2025-12811

Improper Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Delinea Inc. Cloud Suite and Privileged Access Service. If you're not using the latest Server Suite agents, this fix requires that you upgrade to Server Suite 2023.1 (agent 6.0.1) or later. If ...

Affected productsDelinea Cloud Suite and Privileged Access Service version 25.1 HF4 and earlier
Fixed versionsUpgrade to version 25.1 HF5 or later
Vendor guidance

Upgrade to version 25.1 HF5 or later

Delinea Security AdvisoriesCVE-2025-12812
MediumCVSS 5.3

Delinea Cloud Suite and Privileged Access Service - SQL Injection vulnerability - CVE-2025-12812

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Privileged Access Service.

Affected productsDelinea Cloud Suite and Privileged Access Service version 23.1.2 and earlier
Fixed versionsUpgrade to Cloud Suite version 25.1 or later
Vendor guidance

Upgrade to Cloud Suite version 25.1 or later

Delinea Security AdvisoriesCVE-2025-12810
MediumCVSS 5.3

Delinea Secret Server on-prem RPC Password Rotation authentication vulnerability - CVE-2025-12810

Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules). This issue affects Secret Server On-Prem: 11.8.1, 11.9.6, 11.9.25.

Affected productsDelinea Secret Server on-prem versions 11.8.1, 11.9.6, and 11.9.25
Fixed versionsUpgrade to Secret Server version 11.9.47 or later The secret will remain checked out when the password change fails.
Vendor guidance

Upgrade to Secret Server version 11.9.47 or later The secret will remain checked out when the password change fails.

Delinea Security AdvisoriesCVE-2026-2409
CriticalCVSS 9.3

Delinea Cloud Suite on-prem argument injection vulnerability - CVE-2026-2409

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suite allows Argument Injection.

Affected productsCloud Suite before 25.2 HF1Resolution:Upgrade to Cloud Suite version 25.2 HF1 or later
Fixed versionsUpgrade to Cloud Suite version 25.2 HF1 or later
Vendor guidance

Upgrade to Cloud Suite version 25.2 HF1 or later

Delinea Security AdvisoriesCVE-2025-6942
LowCVSS 3.8

Delinea Secret Server on-prem distributed engine authentication process vulnerability - CVE-2025-6942

The distributed engine of Secret Server version 11.7.49 and earlier allows an attacker to impersonate another distributed engine by exploiting a vulnerability in an initial authorization event.

Affected productsDelinea Secret Server on-prem version 11.7.49 and earlier ResolutionUpgrade to Secret Server version 11.7.60 or later
Fixed versionsUpgrade to Secret Server version 11.7.60 or later
Vendor guidance

Upgrade to Secret Server version 11.7.60 or later

Delinea Security AdvisoriesCVE-2025-6943
LowCVSS 3.8

Delinea Secret Server on-prem SQL report creation vulnerability - CVE-2025-6943

Secret Server version 11.7.49 and earlier allows an administrator to gain access to restricted tables by exploiting a vulnerability in the SQL report creation functionality.

Affected productsDelinea Secret Server on-prem version 11.7.49 and earlier ResolutionUpgrade to Secret Server version 11.7.60 or later
Fixed versionsUpgrade to Secret Server version 11.7.60 or later
Vendor guidance

Upgrade to Secret Server version 11.7.60 or later

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.