Executive brief
Secret Server is an enterprise password vault used to store and manage sensitive credentials. Under certain conditions, an attacker with access to a valid SAML identity provider response could exploit a validation weakness to impersonate another user and gain unauthorized access to stored secrets and privileged accounts.
Technical details
This vulnerability is an authentication bypass in Secret Server's SAML identity provider integration. The root cause is insufficient validation of SAML IdP responses, allowing an attacker to craft or intercept a valid SAML response and modify user identity claims to impersonate another user. Attack preconditions likely include network access to Secret Server and ability to influence or intercept SAML authentication flows (e.g., via network position or compromised IdP). Successful exploitation grants full access to the impersonated user's privileges and all accessible secrets within the vault. A patch is expected from Delinea; users should monitor their security advisories and apply updates promptly.
Affected products
- Delinea Secret Server
Timeline
- 2026-09-16: disclosed