MEDIUM🇵🇱 Wersja polska

CVE-2025-12810

CVSS 5.3v4.0pub. 2026-01-27upd. 2026-02-06

Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue affects Secret Server On-Prem: 11.8.1, 11.9.6, 11.9.25. A secret with "change password on check in" enabled automatically checks in even when the password change fails after reaching its retry limit. This leaves the secret in an inconsistent state with the wrong password. Remediation: Upgrade to 11.9.47 or later. The secret will remain checked out when the password change fails.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:X/U:X
  • Delinea Secret Server

    APP
    Delinea
    11.8.00000111.9.00000611.9.000025
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2023-4589CRITICAL9.1PL ✓same product

Delinea Secret Server — brak weryfikacji integralności pakietów aktualizacji

CVE-2024-33891HIGH8.8same product

Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretS...

CVE-2024-25652HIGH7.6same product

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or w...

CVE-2024-12908MEDIUM6.9same product

Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within ...

CVE-2024-25653MEDIUM4.3same product

Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users,...