Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-25652

CVE-2024-25652: Delinea Secret Server Auth Bypass Flaw

CVE-2024-25652 is an authentication bypass vulnerability in Delinea PAM Secret Server 11.4 that allows privileged users to gain unauthorized remote session access. This article covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2024-25652 Overview

CVE-2024-25652 is a broken access control vulnerability in Delinea Secret Server 11.4 that allows authenticated users with elevated reporting privileges to view remote session data belonging to other users. Users assigned the Administer Reports permission, or users operating under UNLIMITED ADMIN MODE with access to the Report functionality, can extract session information through the Custom Legacy Report feature. The flaw is tracked under CWE-287: Improper Authentication and affects on-premises deployments of Delinea Secret Server.

Critical Impact

An authenticated administrator with reporting rights can access remote sessions created by legitimate users, exposing privileged credentials and session data stored in the vault.

Affected Products

  • Delinea Secret Server 11.4.000000 (on-premises)
  • Deployments using the Custom Legacy Report functionality
  • Environments where UNLIMITED ADMIN MODE is enabled

Discovery Timeline

  • 2024-03-14 - CVE-2024-25652 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-25652

Vulnerability Analysis

Delinea Secret Server manages privileged credentials and brokers remote sessions to protected systems. The Custom Legacy Report functionality queries the underlying data store and returns tabular results to authorized users. In version 11.4, the report engine returns data associated with remote sessions initiated by other users, bypassing the session-level access boundary that normally isolates each operator.

An attacker with the Administer Reports permission can craft or run legacy reports that surface session metadata and content belonging to unrelated principals. The same exposure is reachable through UNLIMITED ADMIN MODE, an administrative escape hatch documented by Delinea for break-glass scenarios. Because Secret Server centralizes high-value credentials, unauthorized session visibility can cascade into full compromise of downstream systems.

Root Cause

The root cause is missing authorization enforcement on data returned by the Custom Legacy Report feature. The reporting layer trusts the caller's reporting role and does not re-validate ownership or per-secret ACLs when returning remote session records. This aligns with the CWE-287 classification for improper authentication of the data-access path.

Attack Vector

Exploitation requires network access to the Secret Server web interface, valid credentials, and either the Administer Reports permission or an active UNLIMITED ADMIN MODE session. The attacker interacts with the Custom Legacy Report UI or its underlying endpoints to run a report that returns session data belonging to other users. User interaction from a privileged account is required, which is why the flaw is scoped to insider abuse or compromised administrator accounts.

No public proof-of-concept exploit or CISA KEV listing is available for this issue. See the Delinea CVE-2024-25652 notice for the vendor-referenced advisory.

Detection Methods for CVE-2024-25652

Indicators of Compromise

  • Execution of Custom Legacy Reports by accounts that do not typically use the reporting subsystem.
  • Activation of UNLIMITED ADMIN MODE outside of documented break-glass windows.
  • Reports returning session records for secrets the operator does not own or manage.

Detection Strategies

  • Audit Secret Server event logs for REPORT VIEW and REPORT RUN events tied to the Custom Legacy Report category.
  • Correlate report executions with subsequent access to unrelated secrets or session recordings.
  • Alert on any toggle of UNLIMITED ADMIN MODE and require ticketed justification.

Monitoring Recommendations

  • Forward Secret Server audit logs to a centralized SIEM and retain them for privileged-access review.
  • Establish a baseline of report authors and flag deviations, especially reports touching session tables.
  • Review report definitions weekly for queries that reference session, launcher, or remote-connection objects.

How to Mitigate CVE-2024-25652

Immediate Actions Required

  • Upgrade Delinea Secret Server to the fixed release listed in the February 2024 release notes.
  • Revoke the Administer Reports permission from accounts that do not require it.
  • Disable UNLIMITED ADMIN MODE unless actively needed and enforce dual-control activation per the Delinea admin mode documentation.

Patch Information

Delinea addressed CVE-2024-25652 in the Secret Server update published in the February 2024 release notes. Customers should apply the patched build to all on-premises Secret Server nodes and validate report behavior post-upgrade. Additional advisories are available through the Delinea Trust Portal.

Workarounds

  • Restrict the Administer Reports role to a minimal set of vetted administrators until patching is complete.
  • Remove or disable Custom Legacy Report definitions that query session-related tables.
  • Enforce approval workflows and time-bound activation for UNLIMITED ADMIN MODE.
  • Rotate any secrets that may have been exposed through reports run by non-owners.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.