Delinea Fixes Flaw, But Only After Analyst Goes Public With Disclosure First
ID: 76b6e436-a507-5d14-8a91-c09bab085651
STIX ID: report--76b6e436-a507-5d14-8a91-c09bab085651
Feed Name: Dark Reading
Date Published: 2024-04-16
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
A researcher disclosed a critical authentication/authorization vulnerability in Delinea's Secret Server SOAP API after reporting it to the vendor and working with CERT; Delinea subsequently rolled out an automatic cloud fix and an on‑premises patch. The report highlights delayed or restricted vendor intake for external researchers (researcher was told he couldn't open a case because he wasn't a paying customer), lack of an assigned CVE at the time, and broader strain on vulnerability management processes across the industry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
