CVE-2025-12811: Cloud Suite and Privilege Access Service– HTTP request smuggling vulnerability
Improper Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Delinea Inc. Cloud Suite and Privileged Access Service.
If you're not using the latest Server Suite agents, this fix requires that you upgrade to Server Suite 2023.1 (agent 6.0.1) or later. If you cannot upgrade to Release 2023.1 (agent version 6.0.1) or later, you can choose one of the following versions:
Server Suite release 2023.0.5 (agent version 6.0.0-158)
Server Suite release 2022.1.10 (agent version 5.9.1-337)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12811?
CVE-2025-12811 is categorized as a critical severity vulnerability due to the potential exploitation of HTTP request smuggling.
How do I fix CVE-2025-12811?
To fix CVE-2025-12811, users must update to the latest version of Delinea Cloud Suite or Privileged Access Service agents.
What products are affected by CVE-2025-12811?
CVE-2025-12811 affects Delinea Cloud Suite and Privileged Access Service versions prior to 2023.1.
What kind of vulnerability is CVE-2025-12811?
CVE-2025-12811 is an HTTP request smuggling vulnerability resulting from inconsistent interpretation of HTTP requests.
What are the risks associated with CVE-2025-12811?
Exploitation of CVE-2025-12811 could allow attackers to conduct unauthorized actions on affected services, leading to data breaches or system compromise.