CVE-2025-12811 - CVE House
Back to Database
Status published Medium CVE-2025-12811

Cloud Suite and Privilege Access Service– HTTP request smuggling vulnerability

Vulnerability Description

Improper Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Delinea Inc. Cloud Suite and Privileged Access Service. If you're not using the latest Server Suite agents, this fix requires that you upgrade to Server Suite 2023.1 (agent 6.0.1) or later. * If you cannot upgrade to Release 2023.1 (agent version 6.0.1) or later, you can choose one of the following versions: * Server Suite release 2023.0.5 (agent version 6.0.0-158) * Server Suite release 2022.1.10 (agent version 5.9.1-337)

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12811

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Dawid Dudek

Affected Vendor

Delinea Inc.

View all reports →

Affected Software

Cloud Suite and Privileged Access Service
Vulnerable Versions:
25.1 HF5, 25.1 HF4 and earlier

Timeline

Official Publish: February 18th, 2026
Last Modified: February 19th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)