CVE-2026-15640: Authentication Bypass via SAML Response Manipulation
Published Sep 15, 2026
·Updated
Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Secret Serverto a version that resolves this vulnerability.Fixed in 12.2.7
Event History
Sep 15, 2026
CVE Published
via MITRE·11:22 PM
Data Sourced
via MITRE·11:22 PM
RemedyDescriptionWeakness