secret_server_on-prem vulnerabilities
CVEs whose affected-version data names the secret_server_on-prem package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-15638Critical· 9.1An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys
An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.
▾ MidnightDelinea · Secret Server (On-Prem)EPSS 0.20%via NVD
CVE-2026-15640Critical· 9.5Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
▾ MidnightDelinea · Secret Server (On-Prem)EPSS 0.28%via NVD
CVE-2026-15639Critical· 9.3An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.
An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.
▾ MidnightDelinea · Secret Server (On-Prem)EPSS 0.39%via NVD