{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-19117","assignerOrgId":"1443cd92-d354-46d2-9290-d812316ca43a","state":"PUBLISHED","assignerShortName":"Delinea","dateReserved":"2026-08-06T14:39:05.258Z","datePublished":"2026-09-02T18:04:50.665Z","dateUpdated":"2026-09-02T18:32:08.651Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1443cd92-d354-46d2-9290-d812316ca43a","shortName":"Delinea","dateUpdated":"2026-09-02T18:09:06.788Z"},"title":"Delinea Secret Server FIDO2 credential registration authentication bypass vulnerability","datePublic":"2026-09-02T18:10:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-290","description":"CWE-290 Authentication bypass by spoofing","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-115","descriptions":[{"lang":"en","value":"CAPEC-115 Authentication Bypass"}]}],"affected":[{"vendor":"Delinea","product":"Secret Server (On-Prem)","platforms":["Windows"],"versions":[{"status":"affected","version":"10.6.0","lessThanOrEqual":"11.7.61","versionType":"custom"},{"status":"affected","version":"11.8.0","lessThanOrEqual":"11.8.1","versionType":"custom"},{"status":"affected","version":"11.9.0","lessThanOrEqual":"11.9.47","versionType":"custom"},{"status":"affected","version":"12.0.0","lessThanOrEqual":"12.0.22","versionType":"custom"},{"status":"affected","version":"12.1.0","lessThanOrEqual":"12.1.2","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as\nthat user. This issue affects on-premises deployments only.","supportingMedia":[{"type":"text/html","base64":false,"value":"Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as<br>that user. This issue affects on-premises deployments only."}]}],"references":[{"url":"https://delinea.com/security-advisories","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"CRITICAL","baseScore":9.8,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}}],"solutions":[{"lang":"en","value":"Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.\n\nCustomers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability","supportingMedia":[{"type":"text/html","base64":false,"value":"Upgrade to secret server version 12.2.7 or later, or upgrade to one of the following hotfixes: 12.1.3, 12.0.23, 11.9.48, 11.8.2, or 11.7.62.<br><br>Customers on versions prior to 11.7 should upgrade to a supported version to address this vulnerability<br><br>"}]}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.4"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-02T18:31:57.089249Z","id":"CVE-2026-19117","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-02T18:32:08.651Z"}}]}}