PT-2026-5015 · Delinea · Secret Server On-Prem+1
CVE-2025-12810
·
Publicado
2026-01-27
·
Atualizado
2026-02-06
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Delinea Inc. Secret Server On-Prem versions 11.8.1, 11.9.6, and 11.9.25
Description
An improper authentication issue exists in the RPC Password Rotation modules of Delinea Inc. Secret Server On-Prem. When a secret has the "change password on check in" feature enabled, it can automatically check in even if the password change fails after multiple attempts. This results in the secret remaining in an inconsistent state with an incorrect password.
Recommendations
Upgrade to Secret Server On-Prem version 11.9.47 or later. The secret will remain checked out when the password change fails.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Secret Server On-Prem
Secret Server