CVE-2026-15638

Status: Received

Description

An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.

Published
September 16, 2026 12:17 AM
Last Modified
September 16, 2026 12:17 AM
Source
1443cd92-d354-46d2-9290-d812316ca43a

Weaknesses (CWE)

CWE-327

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.