{"record":"Delinea evidence record","url":"https://nexalign.io/vendors/delinea","vendor":{"slug":"delinea","name":"Delinea","domain":"delinea.com","category":"pam","categoryLabel":"Privileged access management"},"lastChecked":"2026-07-17T16:17:36.246Z","coverage":{"earliest":"2023-09-06T11:43:19.000Z","latest":"2026-07-17T16:17:36.246Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":30,"kindsOfSource":4,"attributedAdvisories":7,"knownExploited":0,"registerEntriesNotAttributable":14,"practitionerThreads":0,"independentItems":3,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":20,"latest":"2026-06-09T23:46:21.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":5,"latest":"2026-06-10T00:16:54.500Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":3,"latest":"2026-07-17T16:17:36.246Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":2,"latest":"2025-01-30T17:46:29.000Z"}],"advisories":{"shown":6,"total":7,"truncated":true,"items":[{"id":"CVE-2026-2409","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suite allows Argument Injection.This issue affects Cloud Suite: before…","severity":"critical","cvss":9.3,"knownExploited":false,"date":"2026-02-19T18:25:00.633Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-2409","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-7802"]},{"id":"CVE-2025-12812","description":"Improper Neutralization of Special Elements used in an SQL Command\n('SQL Injection') in Delinea Inc.","severity":"medium","cvss":5.3,"knownExploited":false,"date":"2026-02-18T23:16:18.763Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-12812","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-207856"]},{"id":"CVE-2025-12811","description":"Improper Inconsistent Interpretation of\nHTTP Requests ('HTTP Request Smuggling') in Delinea Inc.","severity":"medium","cvss":6.9,"knownExploited":false,"date":"2026-02-18T23:16:18.580Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-12811","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-207857"]},{"id":"CVE-2025-12810","description":"Improper Authentication vulnerability in Delinea Inc.","severity":"medium","cvss":6.5,"knownExploited":false,"date":"2026-01-27T20:16:14.320Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-12810","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-206382"]},{"id":"CVE-2025-6942","description":"The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited during an initial authorization event that would allow an attacker to…","severity":"low","cvss":3.8,"knownExploited":false,"date":"2025-07-02T15:49:16.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-19743"]},{"id":"CVE-2025-6943","description":"Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables.","severity":"low","cvss":3.8,"knownExploited":false,"date":"2025-07-02T15:45:01.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-19741"]}]},"practitionerThreads":{"shown":0,"total":0,"truncated":false,"items":[]},"independentCoverage":{"shown":3,"total":3,"truncated":false,"items":[{"title":"Delinea Platform Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/delinea-platform","date":null},{"title":"Delinea Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/it-security/vendor/delinea","date":null},{"title":"Delinea Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/privileged-access-management/vendor/delinea","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 14 register entries mention Delinea without naming a product of Delinea as affected. They are excluded rather than counted as vulnerabilities.","No public practitioner discussion naming Delinea was found in the indexed threads. Operational experience with this product is not represented in this record.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}