CVE-2026-15638: CWE-327 Use of a Broken or Risky Cryptographic Algorithm in Delinea Secret Server (On-Prem)
An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.
AI Analysis
Technical Summary
This vulnerability involves the use of a broken or risky cryptographic algorithm (CWE-327) in Delinea Secret Server (On-Prem). An unauthenticated attacker with access to the server can leverage a padding oracle attack to decrypt or encrypt data with one of the server's cryptographic keys. Although the key is not exposed, the ability to perform cryptographic operations without authorization poses a significant security risk. The affected versions are from 10.5.1 up to and including 12.1.3. The CVSS 4.0 score is 9.1, indicating a critical severity with network attack vector, high complexity, and no privileges or user interaction required.
Potential Impact
An unauthenticated attacker with access to the Secret Server can exploit the padding oracle vulnerability to decrypt or encrypt data using one of the server's cryptographic keys. This could lead to unauthorized cryptographic operations, potentially compromising the confidentiality and integrity of sensitive data managed by the server. The cryptographic key itself is not exposed, but the ability to manipulate encrypted data poses a serious security risk.
Mitigation Recommendations
No explicit patch or remediation information is provided in the vendor advisory or input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the Secret Server to trusted users only and monitor for unusual cryptographic activity.
CVE-2026-15638: CWE-327 Use of a Broken or Risky Cryptographic Algorithm in Delinea Secret Server (On-Prem)
Description
An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.
CVSS v4.0
Score 9.1critical
Affected software
Delinea
Secret Server (On-Prem)
pkg:github/delinea/secret-serverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves the use of a broken or risky cryptographic algorithm (CWE-327) in Delinea Secret Server (On-Prem). An unauthenticated attacker with access to the server can leverage a padding oracle attack to decrypt or encrypt data with one of the server's cryptographic keys. Although the key is not exposed, the ability to perform cryptographic operations without authorization poses a significant security risk. The affected versions are from 10.5.1 up to and including 12.1.3. The CVSS 4.0 score is 9.1, indicating a critical severity with network attack vector, high complexity, and no privileges or user interaction required.
Potential Impact
An unauthenticated attacker with access to the Secret Server can exploit the padding oracle vulnerability to decrypt or encrypt data using one of the server's cryptographic keys. This could lead to unauthorized cryptographic operations, potentially compromising the confidentiality and integrity of sensitive data managed by the server. The cryptographic key itself is not exposed, but the ability to manipulate encrypted data poses a serious security risk.
Mitigation Recommendations
No explicit patch or remediation information is provided in the vendor advisory or input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the Secret Server to trusted users only and monitor for unusual cryptographic activity.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Delinea
- Date Reserved
- 2026-07-13T18:18:20.775Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa9ee1c55bf5e2cf5bd2747
Added to database: 09/16/2026, 01:17:16 UTC
Last enriched: 09/16/2026, 01:31:39 UTC
Last updated: 09/16/2026, 05:01:23 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.