PT-2026-84847 · Delinea · Secret Server On-Prem
CVE-2026-19117
·
Published
2026-09-02
·
Updated
2026-09-04
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Delinea Secret Server On-Prem versions 10.6.0 through 11.7.61
Delinea Secret Server On-Prem versions 11.8.0 through 11.8.1
Delinea Secret Server On-Prem versions 11.9.0 through 11.9.47
Delinea Secret Server On-Prem versions 12.0.0 through 12.0.22
Delinea Secret Server On-Prem versions 12.1.0 through 12.1.2
Description
An authentication bypass exists in on-premises deployments where an attacker can register a FIDO2 credential they control against a target account and subsequently authenticate as that user. This issue occurs during the enrollment stage, where the application incorrectly associates the attacker's public key with the target identity. The attack requires no existing account, no prior privileges, and no victim interaction. Successful exploitation allows the attacker to assume the roles and permissions of the targeted user, potentially granting access to privileged secrets such as domain administrator accounts, private keys, and database credentials. The flaw is related to the FIDO2 registration workflow, specifically involving the registration callback, challenge comparison, and registration-key lifetime.
Recommendations
Update Delinea Secret Server On-Prem versions 10.6.0 through 11.7.61 to version 11.7.62.
Update Delinea Secret Server On-Prem versions 11.8.0 through 11.8.1 to version 11.8.2.
Update Delinea Secret Server On-Prem versions 11.9.0 through 11.9.47 to version 11.9.48.
Update Delinea Secret Server On-Prem versions 12.0.0 through 12.0.22 to version 12.0.23.
Update Delinea Secret Server On-Prem versions 12.1.0 through 12.1.2 to version 12.1.3.
Upgrade to Secret Server version 12.2.7 or later.
Use the Reset Two-Factor Authentication feature to unregister any suspect FIDO2 devices, as simply disabling FIDO2 does not remove the stored registration.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Secret Server On-Prem