CVE-2025-6943
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
02/07/2025
Last modified:
10/10/2025
Description
Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables.
Impact
Base Score 3.x
3.80
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:delinea:secret_server:*:*:*:*:on-premises:*:*:* | 11.7.000060 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://docs.delinea.com/online-help/secret-server-changelog/secret-server-change-log.htm?cshid=secret-server-changelog#Friday,_November_22,_2024
- https://docs.delinea.com/online-help/secret-server/release-notes/ss-rn-11-7-000060.htm
- https://docs.delinea.com/online-help/secret-server/release-notes/ss-rn-11-7-000061.htm
- https://trust.delinea.com



