Exploitation of Secret Server on-prem deployments via CVE-2026-19117
Delinea Logo

Trust Center

ControlK

Delinea's cloud-native identity security platform serves as the central control plane for managing access across human, machine, third-party, and AI identities. By continuously discovering identities, assessing risk, and enforcing least-privilege access in real time, Delinea transforms identity from an organization's greatest vulnerability into its strongest line of defense.

Security is built into everything we do. Delinea maintains a comprehensive Information Security Program aligned to industry-recognized frameworks and designed to protect the confidentiality, integrity, and availability of our systems and customer data. Delinea implements a robust security program that embeds security controls and continuous quality assurance at every stage of the development lifecycle. The safeguards encompass intrusion detection, DDoS prevention, vulnerability management, behavioral analytics, continuous monitoring, cryptographic protections, network security, and configuration management, ensuring our platform remains resilient against evolving threats.

Documents

DOCUMENTS2026 CAIQ

Trust Center Updates

Exploitation of Secret Server on-prem deployments via CVE-2026-19117

Vulnerabilities

Delinea has received reports of customers observing active exploitation of their on-prem Secret Server instances via CVE-2026-19117.

Delinea would like to remind customers that they are highly encouraged to upgrade their Secret Server on-prem to a version that addresses CVE-2026-19117. as described in the advisory.

Delinea Secret Server on-prem FIDO2 credential registration authentication bypass vulnerability - CVE- 2026-19117

Vulnerabilities

Vulnerability Description - Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

Affected product and version
Delinea Secret Server on-prem
10.6.0 through 11.7.61
11.8.0 through 11.8.1
11.9.0 through 11.9.47
12.0.0 through 12.0.22
12.1.0 through 12.1.2

Resolution
Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.
Customers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability

CVE Details

Security Advisory: Klue Vulnerability Incident

Vulnerabilities

 
Delinea does not use the Klue market intelligence platform and has no integrations with it, therefore Delinea is not impacted by the Klue incident disclosed on June 12, 2026.

 
Please subscribe to the Delinea Trust Center for future security and other important announcements.

Notice regarding the recent geopolitical developments in the Middle East

General

Delinea is aware of the current situation in the Middle East and the associated escalation in cyber threat activity targeting technology sector infrastructure. Delinea does not own or operate data centers in the impacted regions but does deliver services via third-party cloud infrastructure providers that might be impacted based on the current threat landscape.

To date, Delinea services in the region have not been impacted, and we continue to actively monitor the situation. Further updates will be provided if and as soon as our impact assessment changes.

If you have further questions, please contact your Customer Success Manager, Engagement Manager, or Partner Manager. Please subscribe to the Delinea Trust Center for future security and other important announcements.

Delinea Cloud Suite on-prem argument injection vulnerability - CVE-2026-2409

Vulnerabilities

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suite allows Argument Injection.

Affected Product and Version

Cloud Suite before 25.2 HF1

Resolution

Upgrade to Cloud Suite version 25.2 HF1 or later

CVE Details

  • CVE ID: CVE-2026-2409
  • Vulnerability Type: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
  • CWE: 89
  • CVSS v4.0 Score: 9.3
  • CVSS v4.0 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
  • Credit: Jess Parker (Reporter), Radu Enachi (Reporter)
  • References: Release Notes
If you need help using this Trust Center, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue
Built onSafeBase by Drata Logo