Description
An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to secret server version 12.2.7 or later.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://delinea.com/security-advisories |
|
History
Tue, 15 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed. | |
| Title | Cryptographic Padding Oracle | |
| Weaknesses | CWE-327 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Delinea
Published:
Updated: 2026-09-16T01:07:45.950Z
Reserved: 2026-07-13T18:18:20.775Z
Link: CVE-2026-15638
No data.
Status : Received
Published: 2026-09-16T00:17:02.600
Modified: 2026-09-16T00:17:02.600
Link: CVE-2026-15638
No data.
OpenCVE Enrichment
No data.
Weaknesses