OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-15640

CRITICAL · CVSS 9.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A vulnerability exists that allows a valid SAML Identity Provider (IdP) response to be exploited for impersonating another user within Secret Server, posing a critical risk to user authentication integrity. This could lead to unauthorized access to sensitive information and resources. Organizations utilizing Secret Server should prioritize immediate remediation to mitigate potential security breaches.

CVE
CVE-2026-15640
Severity
CRITICAL
CVSS
9.5
EPSS
0.28%

Original NVD Description

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.