Executive brief
Delinea's identity and access management platform allows administrators to control user authentication across enterprise systems. Under specific conditions, an attacker can register an unauthorized FIDO2 security key to a legitimate user account and then authenticate as that user without knowing their password. This impacts on-premises deployments only and could allow account takeover and lateral movement within the organization.
Technical details
This vulnerability is an authentication bypass in Delinea's FIDO2 credential management. The root cause appears to be insufficient validation or authorization checks during FIDO2 credential registration, allowing an attacker to associate an attacker-controlled credential with a target account. Once registered, the attacker can authenticate as the target user. The attack vector and preconditions are not fully detailed in the advisory, but the issue is specific to on-premises deployments. Patches or mitigations should be available from Delinea's security advisory page.
Affected products
- Delinea Secret Server <UNKNOWN>
Timeline
- 2026-09-02: disclosed