拥有 Secret Server 访问权限的未经身份验证的用户可以利用填充预言机(padding oracle)漏洞,使用服务器其中一个加密密钥对数据进行解密或加密。密钥本身并未暴露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Delinea | Secret Server (On-Prem) | 10.5.1 ~ 12.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15640 | 9.5 CRITICAL | Authentication Bypass via SAML Response Manipulation |
| CVE-2026-15639 | 9.3 CRITICAL | Reflected Cross-Site Scripting |
No comments yet