Executive brief
Secret Server is a privileged credential management system used to store and control access to sensitive passwords and credentials. An unauthenticated user with network access to the server could exploit a padding oracle vulnerability to decrypt or encrypt data protected by the server's cryptographic keys, potentially compromising the confidentiality of stored secrets without needing to obtain the cryptographic keys themselves.
Technical details
The vulnerability is a padding oracle attack against Secret Server's cryptographic implementation. An unauthenticated attacker with network access to the affected server can craft malicious requests to observe responses that leak information about the padding of encrypted data, enabling decryption or encryption of arbitrary data using the server's cryptographic keys without direct key exposure. The attack requires the ability to send multiple requests and observe response patterns, but does not require authentication. Patches should be available from Delinea.
Affected products
- Delinea Secret Server
Timeline
- 2026-09-16: disclosed