CVE-2025-6942

LOW

Secret Server <11.7.49 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited during an initial authorization event that would allow an attacker to impersonate another distributed engine.

Scores

CVSS v3 3.8
EPSS 0.0007
EPSS Percentile 20.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
Delinea/Secret Server < 11.7.49
Delinea/Secret Server < 8.4.39.0
Published Jul 02, 2025
Tracked Since Feb 18, 2026