External risk intelligence

Secret Server Padding Oracle Allows Data Decryption or Encryption

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-15638

Secret Server is a privileged access management (PAM) solution, which is commonly deployed as a web-based, internet-facing, or externally reachable administrative gateway to manage infrastructure and credentials in enterprise environments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in Secret Server, a tool used for managing sensitive information. This issue could allow an unauthorized individual with access to the system to decrypt or encrypt data without directly obtaining the encryption key. The main concern is to confirm if our organization uses this technology and if it is exposed to potential risks.

  • Unauthenticated access can alter encrypted data.
  • Critical for protecting sensitive credentials and data.
  • Verify usage and exposure of Secret Server.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker with network access to a vulnerable instance of Delinea Secret Server can exploit a padding oracle vulnerability. This allows the attacker to decrypt or encrypt data using the server's cryptographic keys without the keys themselves being exposed. The vulnerability could lead to a compromise of data confidentiality and integrity.

  • Network access required, no authentication.
  • Padding oracle vulnerability is triggered.
  • Data confidentiality and integrity risk.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated user with access to Secret Server could potentially encrypt or decrypt data using the server's cryptographic keys through a padding oracle attack. This could affect the confidentiality and integrity of data managed by the Secret Server when the advisory's conditions are met.

  • Server's cryptographic keys.
  • Leverage a padding oracle attack.
  • Data confidentiality and integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Secret Server, a privileged access management solution, likely impacts infrastructure and security teams. The immediate priority is to identify all instances of Secret Server, determine their reachability and business criticality, and locate the accountable owner for each instance. This will inform a risk-based remediation plan, which may involve coordination with Delinea.

  • Security and infrastructure teams own the issue.
  • Verify Secret Server instance reachability and criticality.
  • Coordinate with Delinea for remediation planning.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Delinea Secret Server?

Secret Server is a privileged access management (PAM) solution. Organizations use it as a secure vault to store, manage, and monitor access to highly sensitive credentials, such as administrative passwords and API keys, across their IT infrastructure.

What does the padding oracle weakness in CVE-2026-15638 mean?

This vulnerability, classified as CWE-327 (Use of a Broken or Risky Cryptographic Algorithm), allows an attacker to misuse the server's encryption processes. By sending specifically crafted requests and analyzing the server's responses, an unauthorized person can trick the system into encrypting or decrypting data without ever needing to steal the actual secret keys.

How is this padding oracle attack triggered?

An attacker initiates this by sending malformed data to the Secret Server application over the network. The vulnerability relies on the server's error responses to these specific inputs. It is important to note that simply visiting the login page or having a valid user account is not the trigger; the attack requires an actor to actively interact with the cryptographic operations through the application's interface.

Is my Secret Server instance at risk?

Halo Surface Signal indicates that Secret Server is often deployed as an internet-facing or externally reachable gateway to manage enterprise credentials. If your instance is accessible from the public internet, it falls into the 'external' classification, making it a higher priority for review compared to instances strictly confined to an internal, isolated network.

What steps should I take if I run Secret Server?

First, locate all running instances of the software and confirm who owns each one. Assess whether these instances are reachable from outside your corporate network. Once you have an inventory, coordinate with your security team and monitor communications from Delinea for specific guidance or software updates to mitigate this vulnerability.

References