Junglewise Threat Intelligence

CVE-2026-15640: Delinea Secret Server SAML identity spoofing

CVE-2026-15640 · Severity: info · Published 2026-09-16

Technologies: Delinea Secret Server. Vendors: Delinea.

Executive brief

Secret Server is an enterprise password vault used to store and manage sensitive credentials. Under certain conditions, an attacker with access to a valid SAML identity provider response could exploit a validation weakness to impersonate another user and gain unauthorized access to stored secrets and privileged accounts.

Technical details

This vulnerability is an authentication bypass in Secret Server's SAML identity provider integration. The root cause is insufficient validation of SAML IdP responses, allowing an attacker to craft or intercept a valid SAML response and modify user identity claims to impersonate another user. Attack preconditions likely include network access to Secret Server and ability to influence or intercept SAML authentication flows (e.g., via network position or compromised IdP). Successful exploitation grants full access to the impersonated user's privileges and all accessible secrets within the vault. A patch is expected from Delinea; users should monitor their security advisories and apply updates promptly.

Affected products

  • Delinea Secret Server

Timeline

  • 2026-09-16: disclosed

References

Related threats