ZeroHour

CVE-2026-15640

moderate

SAML Authentication Bypass in Delinea Secret Server Allows User Impersonation

CVSS 4.0
9.5 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-15640 is a critical (CVSS 4.0: 9.5) authentication bypass flaw (CWE-290) in Delinea Secret Server in which, under certain conditions, a valid SAML Identity Provider response can be used to impersonate another Secret Server user. An attacker with a legitimate SAML response for their own account (or the ability to influence how the response is processed) could authenticate as a different user of the privileged access management platform, potentially gaining access to that user's stored secrets, credentials, and privileged accounts. Exploitation is network-based but has high attack complexity and requires attacker prerequisites, suggesting specific SAML configuration or assertion conditions must be met. The flaw affects organizations deploying Delinea Secret Server with SAML single sign-on enabled; the specific affected versions were not stated in the available data. There is no known public proof of concept and the CVE is not in CISA's Known Exploited Vulnerabilities catalog, indicating no confirmed in-the-wild exploitation at this time.

What to do: Apply the vendor's patched Secret Server release as soon as Delinea publishes the fixed version, prioritizing instances with SAML SSO enabled. Review authentication and audit logs for SAML logins where the authenticated identity does not match the asserted NameID, and validate SAML claim/NameID mapping configuration against vendor guidance. Until patched, consider increasing monitoring on SAML-authenticated sessions or temporarily restricting SAML SSO for high-privilege accounts.

Affected
Delinea Secret Server
Estimated exposure
moderateRoughly thousands to ~10,000+ enterprise deployments (estimated) — Delinea states a customer base on the order of 10,000+ organizations for its PAM products, with only a subset of Secret Server instances (self-hosted login portals) visible in public internet scans, so total deployments plausibly fall in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

Weakness
CWE-290
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.