CVE-2026-15638: Cryptographic Padding Oracle
Published Sep 15, 2026
·Updated
An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.
Affected Software
1 affected component
Thycotic Secret Server
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Secret Serverto a version that resolves this vulnerability.Fixed in 12.2.7
Event History
Sep 15, 2026
CVE Published
via MITRE·11:20 PM
Data Sourced
via MITRE·11:20 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated user who has access to Secret Server can exploit the padding oracle.
2
Does exploitation expose the server's cryptographic key?
No. The issue can allow decryption or encryption using one of the server's cryptographic keys, but the key itself is not exposed.