An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to secret server version 12.0.20 or later.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://delinea.com/security-advisories |
|
History
Tue, 15 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker. | |
| Title | Reflected Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Delinea
Published:
Updated: 2026-09-16T01:06:18.812Z
Reserved: 2026-07-13T18:18:22.770Z
Link: CVE-2026-15639
No data.
Status : Received
Published: 2026-09-16T00:17:03.453
Modified: 2026-09-16T00:17:03.453
Link: CVE-2026-15639
No data.
OpenCVE Enrichment
No data.
Weaknesses