CVE-2025-12812: Cloud Suite and Privilege Access Service – SQL Injection
Published Feb 18, 2026
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Privileged Access Service.
Remediation: This issue is fixed in Cloud Suite: 25.1
Affected Software
2 affected components
Delinea Cloud Suite<25.1
Delinea Privileged Access Service<25.1
Event History
Feb 18, 2026
CVE Published
via MITRE·10:10 PM
Data Sourced
via MITRE·10:10 PM
DescriptionWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-12812?
CVE-2025-12812 is classified as a critical SQL Injection vulnerability.
2
How do I fix CVE-2025-12812?
To fix CVE-2025-12812, upgrade to Cloud Suite or Privileged Access Service version 25.1 or later.
3
What products are affected by CVE-2025-12812?
CVE-2025-12812 affects Delinea Cloud Suite and Delinea Privileged Access Service versions prior to 25.1.
4
What kind of vulnerability is CVE-2025-12812?
CVE-2025-12812 is an SQL Injection vulnerability caused by improper neutralization of special elements in SQL commands.
5
Is CVE-2025-12812 still a risk if I update to version 25.1?
No, updating to version 25.1 or later resolves the CVE-2025-12812 vulnerability.