Delinea, Inc.

First CVE: Mar 14, 2024Active for: 2 years
9
CVEs Published
More CVEs Published than 25% of tracked CNAs
3.0
Avg CVEs / Year
More Avg CVEs / Year than 19% of tracked CNAs
6.6
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Delinea, Inc. as a CNA, 55.6% affect products that Delinea, Inc. develops as a vendor.

55.6%
44.4%
Self-reported: 5Third-party: 4

Of all the CVEs published that affect products developed by Delinea, Inc., 35.7% are self-published by Delinea, Inc. as a CNA.

35.7%
64.3%
Self-published: 5Published by other CNAs: 9

Trends Over Time

The number and severity of CVEs published by Delinea, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2024
2 years ago
Most Recent CVE
Feb 19, 2026
155 days ago

Top CVEs

All CVEs published by Delinea, Inc. as a CNA, regardless of affected vendor or product.

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suite allows Argument Injection.This issue affects Cloud Suite:
Feb 19, 20269.329NONO
Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within the protocol handler function, URI's were compared before normalizatio
Dec 26, 20248.325NONO
Improper Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Delinea Inc. Cloud Suite and Privileged Access Service. If you're not using the latest Server S
Feb 18, 20266.922NONO
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with acce
Mar 14, 20248.421NONO
Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue affects Secret Server On-Prem: 11.8.1, 11.9.6, 11.9.25. A se
Jan 27, 20266.520NONO
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Privileged Access Service. Remediation: This issue is fixed i
Feb 18, 20265.319NONO
Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.
Nov 18, 20246.519NONO
Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables.
Jul 2, 20254.016NONO
The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited during an initial authorization event that would allow an attack
Jul 2, 20253.814NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA9 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local3 (33.3%)
Network6 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (77.8%)
High2 (22.2%)
Unknown0 (0.0%)
User Interaction
None4 (44.4%)
Unknown0 (0.0%)
Required5 (55.6%)
Privileges Required
Low2 (22.2%)
High4 (44.4%)
None3 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Delinea, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Delinea, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs