CVE-2026-2409: Delinea Cloud Suite

Critical severity, CVSS 9.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suite allows Argument Injection.This issue affects Cloud Suite: before 25.2 HF1.

Affected products

  • Delinea Cloud Suite: before 25.2 HF1 (fixed in 25.2 HF1)

Published 2026-02-19. Last modified 2026-06-17.