External risk intelligence

Secret Server SAML IdP Response Impersonation Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.5)

CVE-2026-15640

Secret Server is a privileged access management solution typically deployed as a centralized, internet-facing or externally reachable gateway for identity and administrative access. SAML integration is a standard, public-facing component of these services, making the identity portal directly reachable in normal deployments.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in Secret Server that could allow an attacker to impersonate another user by exploiting a valid SAML response. Given that Secret Server often manages privileged access and integrates with standard identity protocols like SAML, understanding the potential for unauthorized access is important. The main concern is to confirm if your environment uses this technology and is exposed.

  • A security flaw can let users impersonate others.
  • It affects systems managing privileged access.
  • Confirm if this technology is used and exposed.

Attack Path

How an attacker could exploit the issue

An attacker could impersonate another user by leveraging a valid SAML response. This occurs when the SAML Identity Provider generates a response under specific conditions that allows for this impersonation. The vulnerability could lead to significant risks if exploited, as it allows an attacker to gain unauthorized access as another user.

  • An attacker needs a valid SAML response.
  • A SAML Identity Provider response triggers the issue.
  • Risk of impersonating other users.

Live Threat

Current exploitation, exposure, and threat context

Under certain conditions, a valid SAML Identity Provider response could be used to impersonate another Secret Server user. This could affect access to sensitive information and service behavior.

  • User impersonation.
  • Through a valid SAML IdP response.
  • Unauthorized access to system data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability, allowing SAML IdP responses to impersonate users, impacts Secret Server, a Privileged Access Management solution. Owners of this technology, likely Platform or Infrastructure teams, must first identify all instances of Secret Server within the environment. Confirming external reachability and business criticality is the immediate next step to prioritize remediation efforts and assign accountability.

  • Platform/Infrastructure teams own the issue.
  • Verify external reachability and criticality first.
  • Plan targeted remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Secret Server?

Secret Server is a Privileged Access Management (PAM) solution. Organizations use it to centralize, secure, and manage administrative credentials and high-level access to critical infrastructure. Because it acts as a gateway for sensitive identity and administrative tasks, it often serves as the backbone for controlling who can access key internal systems.

What does CWE-290 mean for CVE-2026-15640?

CVE-2026-15640 involves CWE-290, which is an Authentication Bypass by Spoofing. In simple terms, the software fails to properly verify the identity claims within a SAML response. This allows an attacker to manipulate or leverage a valid response from an Identity Provider to pose as a different, authorized user within the application, effectively bypassing normal login security.

How does an attacker trigger this vulnerability?

An attacker needs a valid SAML response from an Identity Provider to attempt impersonation. The vulnerability is triggered under specific conditions where the system incorrectly processes this response. Crucially, simply having a standard SAML configuration does not automatically trigger the bug; the system must encounter the specific, flawed set of conditions defined in the advisory during the authentication process.

Is my Secret Server instance at risk?

According to Halo Surface Signal, Secret Server is often deployed as an internet-facing gateway to facilitate remote identity and administrative access. If your instance is externally reachable, it is in a higher-risk category because the identity portal is directly exposed to public network traffic, making it a more accessible target for this type of authentication-based attack.

What should I do if I run Secret Server?

Your first step is to identify all Secret Server instances currently running in your environment. Once identified, verify which ones are reachable over the internet versus those that are internal-only. Use this data to assess the business criticality of each instance and coordinate with your infrastructure or platform teams to plan and prioritize the necessary security updates.

References