CVE-2026-19117: Delinea Secret Server On-Prem
Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.
Affected products
- Delinea Secret Server On-Prem: from 10.6.0, up to and including 11.7.61; from 11.8.0, up to and including 11.8.1; from 11.9.0, up to and including 11.9.47; from 12.0.0, up to and including 12.0.22; from 12.1.0, up to and including 12.1.2
Published 2026-09-02. Last modified 2026-09-03.