CVE-2026-19117

Summary

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

Affected Software

VendorProductVersion RangeStatus
DelineaSecret Server (On-Prem)10.6.0 <= 11.7.61affected
DelineaSecret Server (On-Prem)11.8.0 <= 11.8.1affected
DelineaSecret Server (On-Prem)11.9.0 <= 11.9.47affected
DelineaSecret Server (On-Prem)12.0.0 <= 12.0.22affected
DelineaSecret Server (On-Prem)12.1.0 <= 12.1.2affected

Weaknesses

  • CWE-290: CWE-290 Authentication bypass by spoofing

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References