logo

Delinea Fixes Flaw, But Only After Analyst Goes Public With Disclosure First

ID: 76b6e436-a507-5d14-8a91-c09bab085651

STIX ID: report--76b6e436-a507-5d14-8a91-c09bab085651

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-04-16

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

A researcher disclosed a critical authentication/authorization vulnerability in Delinea's Secret Server SOAP API after reporting it to the vendor and working with CERT; Delinea subsequently rolled out an automatic cloud fix and an on‑premises patch. The report highlights delayed or restricted vendor intake for external researchers (researcher was told he couldn't open a case because he wasn't a paying customer), lack of an assigned CVE at the time, and broader strain on vulnerability management processes across the industry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.