CVE-2026-19117: Delinea Secret Server FIDO2 credential registration authentication bypass vulnerability
Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delinea Secret Serverto a version that resolves this vulnerability.Fixed in 12.2.7Patch 12.2.7 or later - Upgrade
Upgrade
Delinea Secret Serverto a version that resolves this vulnerability.Fixed in 12.1.3Patch hotfix - Upgrade
Upgrade
Delinea Secret Serverto a version that resolves this vulnerability.Fixed in 12.0.23Patch hotfix - Upgrade
Upgrade
Delinea Secret Serverto a version that resolves this vulnerability.Fixed in 11.9.48Patch hotfix - Upgrade
Upgrade
Delinea Secret Serverto a version that resolves this vulnerability.Fixed in 11.8.2Patch hotfix - Upgrade
Upgrade
Delinea Secret Serverto a version that resolves this vulnerability.Fixed in 11.7.62Patch hotfix
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects on-premises deployments of Delinea Secret Server only. The provided information does not identify any other deployment types as affected.
What must an attacker be able to do to exploit this issue?
Under specific conditions, the attacker must be able to register an attacker-controlled FIDO2 credential against a target account. They can then use that credential to authenticate as the target user.
Does exploitation require prior authentication or user interaction?
The supplied severity vector indicates no privileges are required and no user interaction is required. It also rates the attack vector as network-accessible and attack complexity as low.