VendorsDelineasecret_serverall versions
Vulnerabilities

Delinea Secret Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2023-4589
Insufficient verification of data authenticity vulnerability in Delinea Secret Server
Published 2023-09-06 · Modified
9.1EPSS 0.003
CVE-2024-33891
Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService.asmx. This is related to a hardcoded key, the use of the integer 2 for the Admin user, and removal of the oauthExpirationId attribute.
Published 2024-04-28 · Analyzed
8.8EPSS 0.010
CVE-2024-25652
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users through information obtained from the Custom Legacy Report functionality.
Published 2024-03-14 · Analyzed
8.4EPSS 0.006
CVE-2024-12908
Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within the protocol handler function, URI's were compared before normalization and canonicalization, potentially leading to over matching against the approved list. If this attack were successfully exploited, a remote attacker may be able to convince a user to visit a malicious web-page, or open a malicious document which could trigger the vulnerable handler, allowing them to execute arbitrary code on the user's machine. Delinea added additional validation that the downloaded installer's batch file was in the expected format.
Published 2024-12-26 · Analyzed
8.3EPSS 0.007
CVE-2023-4588
File accessibility vulnerability in Delinea Secret Server
Published 2023-09-06 · Modified
6.8EPSS 0.003
CVE-2024-25649
In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption key of RabbitMQ queue messages, and session cookies.
Published 2024-03-14 · Analyzed
6.7EPSS 0.001
CVE-2025-12810
Failure in Password Rotation and Check-in Mechanism in Secret Server Allows Reuse of Credentials
Published 2026-01-27 · Analyzed
6.5EPSS 0.005
CVE-2024-25650
Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmetric Key (used to encrypt RabbitMQ messages) via crafted payloads to the /pre-authenticate, /authenticate, and /execute-and-respond REST API endpoints. This makes it possible for a PAM administrator to impersonate the Engine and exfiltrate sensitive information from the messages published in the RabbitMQ exchanges, without being audited in the application.
Published 2024-03-14 · Analyzed
5.9EPSS 0.003
CVE-2024-25651
User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user is valid because of a difference in responses from the /oauth2/token endpoint.
Published 2024-03-14 · Analyzed
5.3EPSS 0.005
CVE-2024-25653
Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is enabled, to view system reports and modify custom reports via the Report functionality in the Web UI.
Published 2024-03-14 · Analyzed
4.3EPSS 0.004
CVE-2025-6943
Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables.
Published 2025-07-02 · Analyzed
4.0EPSS 0.002