CVE-2026-15640
moderateSAML Authentication Bypass in Delinea Secret Server Allows User Impersonation
CVE-2026-15640 is a critical (CVSS 4.0: 9.5) authentication bypass flaw (CWE-290) in Delinea Secret Server in which, under certain conditions, a valid SAML Identity Provider response can be used to impersonate another Secret Server user. An attacker with a legitimate SAML response for their own account (or the ability to influence how the response is processed) could authenticate as a different user of the privileged access management platform, potentially gaining access to that user's stored secrets, credentials, and privileged accounts. Exploitation is network-based but has high attack complexity and requires attacker prerequisites, suggesting specific SAML configuration or assertion conditions must be met. The flaw affects organizations deploying Delinea Secret Server with SAML single sign-on enabled; the specific affected versions were not stated in the available data. There is no known public proof of concept and the CVE is not in CISA's Known Exploited Vulnerabilities catalog, indicating no confirmed in-the-wild exploitation at this time.
What to do: Apply the vendor's patched Secret Server release as soon as Delinea publishes the fixed version, prioritizing instances with SAML SSO enabled. Review authentication and audit logs for SAML logins where the authenticated identity does not match the asserted NameID, and validate SAML claim/NameID mapping configuration against vendor guidance. Until patched, consider increasing monitoring on SAML-authenticated sessions or temporarily restricting SAML SSO for high-privilege accounts.
| Delinea Secret Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
- Weakness
- CWE-290
- Vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.