Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue affects Secret Server On-Prem: 11.8.1, 11.9.6, 11.9.25. A secret with "change password on check in" enabled automatically checks in even when the password change fails after reaching its retry limit. This leaves the secret in an inconsistent state with the wrong password. Remediation: Upgrade to 11.9.47 or later. The secret will remain checked out when the password change fails.
History

Tue, 27 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 27 Jan 2026 21:00:00 +0000


Tue, 27 Jan 2026 20:00:00 +0000

Type Values Removed Values Added
Description Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue affects Secret Server On-Prem: 11.8.1, 11.9.6, 11.9.25. A secret with "change password on check in" enabled automatically checks in even when the password change fails after reaching its retry limit. This leaves the secret in an inconsistent state with the wrong password. Remediation: Upgrade to 11.9.47 or later. The secret will remain checked out when the password change fails.
Title Failure in Password Rotation and Check-in Mechanism in Secret Server Allows Reuse of Credentials
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/AU:Y/R:A'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Delinea

Published:

Updated: 2026-01-27T20:51:42.590Z

Reserved: 2025-11-06T16:31:41.109Z

Link: CVE-2025-12810

cve-icon Vulnrichment

Updated: 2026-01-27T20:35:42.449Z

cve-icon NVD

Status : Received

Published: 2026-01-27T20:16:14.320

Modified: 2026-01-27T21:15:55.767

Link: CVE-2025-12810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.