An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://delinea.com/security-advisories |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-16 00:17
Updated : 2026-09-16 00:17
NVD link : CVE-2026-15638
Mitre link : CVE-2026-15638
CVE.ORG link : CVE-2026-15638
JSON object : View
Products Affected
No product.
CWE
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
