Junglewise Threat Intelligence

CVE-2026-15638: Delinea Secret Server padding oracle vulnerability

CVE-2026-15638 · Severity: info · CVSS 0 · Published 2026-09-16

Technologies: Delinea Secret Server. Vendors: Delinea.

Executive brief

Secret Server is a privileged credential management system used to store and control access to sensitive passwords and credentials. An unauthenticated user with network access to the server could exploit a padding oracle vulnerability to decrypt or encrypt data protected by the server's cryptographic keys, potentially compromising the confidentiality of stored secrets without needing to obtain the cryptographic keys themselves.

Technical details

The vulnerability is a padding oracle attack against Secret Server's cryptographic implementation. An unauthenticated attacker with network access to the affected server can craft malicious requests to observe responses that leak information about the padding of encrypted data, enabling decryption or encryption of arbitrary data using the server's cryptographic keys without direct key exposure. The attack requires the ability to send multiple requests and observe response patterns, but does not require authentication. Patches should be available from Delinea.

Affected products

  • Delinea Secret Server

Timeline

  • 2026-09-16: disclosed

References

Related threats