Delinea has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 9.3 (critical), with 3 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.3
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2026-15640Critical· 9.5Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.52CVE-2026-15639Critical· 9.3An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.51CVE-2026-15638Critical· 9.1An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys50
Delinea vulnerabilities
CVEs affecting Delinea, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-15638Critical· 9.1An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys
An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.
CVE-2026-15640Critical· 9.5Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
CVE-2026-15639Critical· 9.3An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.
An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.