PT-2026-5015 · Delinea · Secret Server On-Prem+1

CVE-2025-12810

·

Publicado

2026-01-27

·

Atualizado

2026-02-06

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Delinea Inc. Secret Server On-Prem versions 11.8.1, 11.9.6, and 11.9.25
Description An improper authentication issue exists in the RPC Password Rotation modules of Delinea Inc. Secret Server On-Prem. When a secret has the "change password on check in" feature enabled, it can automatically check in even if the password change fails after multiple attempts. This results in the secret remaining in an inconsistent state with an incorrect password.
Recommendations Upgrade to Secret Server On-Prem version 11.9.47 or later. The secret will remain checked out when the password change fails.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-12810

Produtos afetados

Secret Server On-Prem
Secret Server