Secret Server 12.2.000007 Release Notes
Release Date: On-premises: August 28, 2026
Component Versions
Secret Server component versions. This does not cover SQL Server, .NET, or operating system requirements, which are in the system requirements documentation.
Distributed Engine and Advanced Session-Recording Agent: 8.5.1.0
Protocol Handler: 6.0.3.56
Upgrade Requirements
Steps you must complete before installing this release, including any intermediate version you have to pass through first. It does not describe the upgrade procedure itself.
- Step upgrade required. Versions prior to 11.9.000025 must upgrade to 11.9.000006 first. Automatic downloads in the product retrieve the correct versions for the step upgrade and then allow upgrades to later versions. Offline installations using the file upload method will otherwise fail with "Integrity Check failed - Security Catalog is signed by thumbprint that is not specifically trusted."
- Protocol Handler 6.0.3.26 and lower must be upgraded manually. Automatic upgrade does not work at or below 6.0.3.26. Version 6.0.3.27 and higher upgrade automatically.
New Features
Capabilities that did not exist in an earlier release. Modifications to capabilities you already have are under Changes.
Administration and Infrastructure
- Azure Managed Identity Authentication allows Azure SQL Database connections to authenticate without SQL credentials in the connection string. Token acquisition, caching, and refresh are handled by the database driver. Supported on Azure VMs with a system-assigned managed identity and on Azure Arc-enrolled servers. Configure it through the combined installer, the setup wizard, or Admin > Configuration > Database by selecting Managed Identity.
API and Automation
- Platform Group Membership Actions let event pipelines add a user to, or remove a user from, a Platform group when users and groups are managed in Platform.
- RDP Web API Endpoints replace the legacy
rdpwebservice.asmxservice.
Authentication and Access Control
- Multiple SAML Certificates can now be configured for a single identity provider, including through settings import and export.
- SAML Auto-Redirect Control adds a
DisableAutoRedirectsetting that skips the automatic redirect to the identity provider and instead renders each active identity provider as a selectable link on the local login page.
Launchers and Remote Access
- RD Gateway Protocol Support is available for the RDP Proxy with a Distributed Engine newer than 8.4.97.0, including per-site and per-engine configuration and certificate handling.
- VNC Launcher adds a VNC launcher type, including support for searching its session recordings.
- VNC Launcher Credential Delivery passes connection credentials from the VNC launcher to Privileged Remote Access sessions.
Changes
Modifications to behavior that already existed—renamed items, relocated settings, altered defaults, and refinements to existing capability. Entries beginning Action Required: need something from you before or after upgrading. New capability is under New Features. Corrections to faulty behavior are under Bug Fixes.
The ID column shows the internal tracking number for each item. You can reference these numbers when contacting Delinea Support.
| ID | Title | Release Notes |
|---|---|---|
| 637026 | Create Metadata API Error Messages and Documentation | Swagger documentation for metadata creation has been expanded, and errors returned from incorrect calls to the create metadata endpoint are now more useful. |
| 639145 | Distributed Engine Updates Wait for Active Proxy Sessions to End | Distributed Engine updates no longer disconnect active SSH and RDP proxy sessions. An update waits until all proxy sessions have closed and then installs immediately. To let a pending update proceed sooner, terminate the sessions with the Terminate Session action on the secret, available from the Active Secret Sessions report. Cancel Update now also stops a pending update, and the engine no longer restarts unless a configuration has actually changed. |
| 646843 | Search Performance After Upgrade | Addressed search slowness reported after upgrade. For best search performance, select Prefer full text when available in Settings > Secret Search Indexer. |
| 668197 | SSH Password Prompt Matching for Localized Systems | A new advanced setting lets the SSH password-prompt pattern match prompts that do not include the username, which resolves su failures on systems with non-English locale settings. |
| 684702 | Session Recordings Survive a Loss of Database Connectivity | Recorded SSH and RDP session segments captured while the database is unavailable are now buffered and retried instead of discarded, and a recovery scan uploads any segments left behind. Recordings that previously became corrupted during a database outage now remain continuous and playable. |
| 686248 | Audit Retrieval Query Performance | Audit retrieval performance has been increased to prevent timeouts. |
| 696919 | Dynamic Field Mapping From Scanners to Discovered Items | Discovery field mapping from scanners to discovered items has been extended, so scan template tokens can be used in PowerShell account, machine, and host scanners. |
| 698668 | Disaster Recovery Replication Performance for Secret Items | Removed an algorithmic bottleneck in secret item replication. Full replication on very large datasets now completes in a fraction of the time it previously took. |
| 711342 | Protocol Handler Domains Populate Automatically From Your Custom URL | Action Required: The default for preventing direct API authentication has changed; review this setting after upgrading. Protocol Handler domains now auto-populate from your custom URL. On-premises URL changes update the domains automatically, and new cloud instances are pre-configured. |
| 714387 | Distributed Engine Migration Reuses Existing Healthy Engine Pools | Distributed Engine migration now detects and reuses existing healthy engine pools. |
| 718309 | Event Pipeline Activity Logs Show Absolute Timestamps | Event Pipeline activity logs now show absolute timestamps in the administrator's configured time zone, along with policy attribution, action details, and search. |
| 719266 | Folder Picker Supports Tree Selection and Search | The folder selector now supports tree selection, searching, and searching within folders for subfolders. |
| 720786 | Force Check In and Request Force Checkout Buttons Use the Warning Style | The Force Check In and Request Force Checkout buttons now use the warning style so they are visually distinct from regular check in and check out actions. |
| 721741 | Diagnostics for Targets With NTLM Disabled | Identified and addressed the areas affected when NTLM v1 and v2 are disabled, changing the diagnostics returned for heartbeat, password change, and Discovery operations against those targets. |
| 724102 | Secret Server Inventory Payloads Include the Platform Site ID | Secret Server inventory payloads now include the platform site ID for site correlation. |
| 724624 | Reliability of Session Recording Sync With Platform Insights | Added reliability and correctness changes to the synchronization of Secret Server session recordings with Delinea Platform Insights. |
| 725218 | Inherit Permissions Indication for Folders and Secrets | The folder and secret edit screens now make it clear whether permissions are inherited, along with broader changes to the inherit permissions system. |
| 725655 | DelineaSecret Server Provisioning Through the Platform Upgrade Center | DelineaSecret Server instances can now access the Platform Upgrade Center and provision a new tenant. |
| 725700 | Platform Upgrade Center Log Refresh and Log Level Display | Platform Upgrade Center logs now use the standard refresh control, and the log level is shown as a chip. |
| 725920 | Error Logging for RDP Proxy Certificate Generation | Certificate generation errors in the RDP Proxy query handler are now logged instead of suppressed. |
| 726412 | Control Over Whether the Secret Port Overrides the Password Changer Port | A configuration switch now determines whether the port field on an SSH secret takes precedence over the port on the password changer for remote password changing and heartbeat. |
| 726448 | Teams Incompatible Messages List the Skipped Permissions | Platform Upgrade Center log messages about incompatible Teams users and groups now list the specific permissions that were skipped. |
| 727530 | Group Names in Users and Groups Grids Are Now Links | Group names in Users and Groups grids now open a window with group information. |
| 727670 | Secret Export Skips Secrets With List-Only Access | Secret export to XML now skips secrets the user has only List access to, which resolves an edge case that caused exports to fail and generate very large in-progress cache entries. |
| 728129 | Memory Efficiency of Disaster Recovery Replication | Disaster Recovery replication now uses memory more efficiently during large syncs. |
| 728134 | Disaster Recovery Save Operations at Very Large Scale | Disaster Recovery replication uses significantly less memory at scale, allowing the largest installations to complete DR Save operations reliably. |
| 729052 | Distributed Locking Prevents Duplicate Folder Creation | Folder uniqueness now uses a distributed lock provider — Redis in cloud and the database on premises — to prevent the race condition that could create duplicate folders. |
| 730070 | Consistent IBM Branding in the Platform Upgrade Center | The Platform Upgrade Center now consistently displays IBM branding on IBM tenants, including the DelineaSecret Server and IBM Verify Privileged Identity Platform product names and IBM logos and styling throughout the upgrade workflow and the user profile. |
| 730103 | Performance Loading Secret Email Settings | Removed an unnecessary call when loading secret email settings. |
| 730104 | Performance Loading RDP and SSH Launcher Settings | Eliminated redundant launcher type reads in the RDP and SSH launcher handlers. |
| 731231 | Report Tab Renamed to Result to Match Platform | The report View report tab has been renamed to Result to match the equivalent Platform report tab. |
| 731749 | External Secrets Can Link to Existing Entries in an External Vault | Azure Key Vault secret name validation now runs per vault, and creating an external secret links to an already existing entry in the external vault instead of denying the request. |
| 732852 | SDK Client Account Revocation When Deleting an Onboarding Rule | Action Required: Deleting an SDK onboarding rule no longer revokes registered SDK client accounts by default. If you rely on the previous behavior, opt in with the new checkbox in the delete dialog or by passing revokeAccounts=true on the API. |
| 732914 | Clear Status for Heartbeat and Password Change Failures on NTLM-Disabled Targets | Heartbeat and password change failures against Windows targets with NTLM disabled now return an AuthProtocolUnavailable status with an actionable administrator message instead of a generic unknown error. |
| 733579 | Certificate Requirement Warning When Enabling RDP Gateway | Enabling RDP Gateway now warns that there are specific, non-bypassable certificate requirements and links to the documentation, instead of allowing the default certificate to fail silently. |
| 735512 | Azure Account Registration Secret Template Renamed | Action Required: Update any script or integration that references the Azure secret template by name. The template was renamed to differentiate it from a similar Azure account template. |
| 736657 | SSH Proxy Password Prompt Setting Applies to su as Well as sudo | On-premises only. The SSH proxy password-prompt setting now applies to su commands in addition to sudo commands. |
Bug Fixes
Defects corrected in this release. Behavior that worked as designed but now works differently is listed under Changes.
| ID | Title | Release Notes |
|---|---|---|
| 561891 | Site Limit License Check Enforced on Disaster Recovery Replicas | The site limit license check is no longer enforced on Disaster Recovery replicas. |
| 584429 | Account Rule Matches Preview Showed More Accounts Than the Import Would Create | The Account Rule Matches preview now applies the same filters as the import, so the preview count matches the accounts actually created. |
| 587675 | RDP Proxy Rejected Hosts Using Remote Desktop Authentication Certificates | With Validate Remote Certificates enabled, the RDP Proxy no longer rejects target hosts whose TLS certificate uses the Remote Desktop Authentication Enhanced Key Usage. |
| 605854 | Reported Vulnerabilities in the Workflow Component | Fixed security vulnerabilities reported against the Secret Server workflow component. |
| 634266 | PowerShell Password Changers Ignored the Configured Heartbeat Interval | Fixed an issue where PowerShell-based password changers with heartbeat enabled re-checked every few minutes instead of honoring the configured heartbeat interval. Secrets on templates already affected in production need the template re-saved to pick up the corrected interval. |
| 640607 | Duplicate Folder Path Errors During Disaster Recovery | Fixed an issue where a race condition could produce duplicate folder paths during Disaster Recovery replication. |
| 643200 | SDK Client Tokens Remained Active After Deleting an Onboarding Rule | Fixed an issue where deleting an SDK onboarding rule left access active for SDK client accounts created through that rule. |
| 650946 | Access Denied on Windows Local Account Password Changes for Domain-Joined Machines | Fixed an issue where the Windows Local Account remote password changer returned Access Denied when the target machine is joined to a domain. This affected Windows Server 2025, where the legacy method is blocked by default. |
| 652643 | Zero-Data ASRA Sessions Appeared as Live in Platform Insights | Fixed an issue where ASRA-recorded sessions that disconnect before any frames or segments arrive appeared as Live sessions in Platform Insights. |
| 668911 | SAML Users Remained Locked Out After the Lockout Timeout Passed | Fixed an issue where SAML users were kept locked out after a successful login once the lockout timeout had passed. |
| 668995 | Session Connector Shadow Users Were Not Cleaned Up on Disconnect | Fixed an issue where shadow users created by the session connector were not cleaned up when a user disconnects, preventing users from being logged off as expected. |
| 676017 | SSH Public Key Import Failed Through Discovery Rules | Fixed an issue that prevented SSH key import through Discovery rules. |
| 683340 | Custom Scanner Names Displayed as Language Resource Not Found | Fixed an issue where custom scanner and scan template names in Network Discovery results displayed Language Resource Not Found instead of the configured name. |
| 688558 | Duplicate Ticket Number Prompt During Access Request Checkout | Fixed an issue where users were prompted twice for a ticket number. The checkout comment dialog now pre-fills the ticket number from the access request. |
| 694168 | CSV Download Failed for Reports Using the DECLARE Keyword | Fixed an issue where the CSV download failed for reports whose SQL used the DECLARE keyword. |
| 694949 | Heartbeat Through the SSH Proxy Failed With FIPS Compliance Enabled | Fixed an issue where heartbeating secrets through the proxy failed with FIPS compliance enabled. |
| 698169 | Dashboard Report in Full Screen Overlapped Other Reports | Fixed an issue where opening a report in full screen from the dashboard overlapped the other reports on the dashboard. |
| 699051 | SSH Key Rotation Required a Password on No Password Templates | Fixed an issue where an associated secret on an SSH Key No Password template required a password to set up SSH key rotation. |
| 702005 | Irreversible User Lockout Caused by Inconsistent FIDO2 Enrollment | Fixed an issue where users could enroll an authenticator they could not subsequently use to sign in. FIDO enrollment now restricts authenticator types to the same level as login flow validation. |
| 702276 | Dependency Changers Stripped Characters After the @ Symbol in Usernames | Fixed an issue where dependency changers stripped characters at or after the @ character in UPN values, so they now load the same username as the remote password changer workflow. |
| 704528 | Approval Dialog Became Unresponsive for Expired Ticket Override Requests | Fixed an issue where approving an expired ticket override request left the dialog unresponsive. The request list now also refreshes after a denial. |
| 704664 | Fresh On-Premises Installations Failed at Database Setup With Windows Authentication | On-premises only. Fixed an issue where fresh installations using Windows Authentication failed at the database setup step with a login failure. SQL Authentication installations were not affected. |
| 704824 | Check-In Prompted for a Comment When One Was Not Required | Fixed an issue where secrets requiring checkout prompted for a comment in the secret grid preview panel when no comment was required. |
| 708250 | Cancel Button Did Not Stop Deactivating an Event Pipeline | Fixed an issue where clicking Cancel while deactivating a pipeline still deactivated it. |
| 714096 | Force Inactivity Timeout Was Visible in Platform | Fixed an issue where the Force inactivity timeout minutes setting was visible in Platform. It is now always hidden. |
| 716097 | Automatic Distributed Engine Upgrade Failed on Windows Server 2025 | Fixed an issue where the Distributed Engine installer was incompatible with Windows Server 2025, preventing automatic engine upgrades from completing. |
| 716339 | Left Navigation Did Not Render When the License Page Loaded First | Fixed an issue where navigating to the license page as the first page after login hid the left navigation until the page was clicked. |
| 720163 | Distributed Engine Configuration Changes Were Not Audited | Fixed an issue where changes to Distributed Engine configuration fields produced no audit records. |
| 720221 | Application Pool Discovery Failed With a Null Reference Error | Fixed an issue where a null reference error caused application pool scanning to fail during engine-based Discovery scans. |
| 720989 | Recently Discovered Windows Accounts Required a Filter to Appear in Network View | Fixed an issue in the Discovery Network View query that prevented Windows accounts from appearing without applying a filter first. |
| 721422 | Inconsistent Descriptions of User Status | Fixed an issue where user state and status descriptions differed across pages. |
| 724139 | Secret Policy Could Not Be Applied to a Folder With Default Only Unchecked | Fixed an issue where a secret policy could not be applied to a folder through the API or the UI when the RPC Privileged Account Default only option was unchecked. |
| 724264 | Secret Download Omitted Extended Fields | Fixed an issue where secret downloads excluded extended fields. |
| 724304 | File Restriction Size Used Bytes in the API but Megabytes in the UI | Fixed an issue where the file restriction size field in the UI did not match the units used by the API. |
| 724380 | Group Owners Could Modify Groups Outside Their Authorized Scope | Fixed an issue in group management where a user with group ownership permissions could modify groups outside their authorized scope. |
| 724663 | Non-ASCII Characters Were Garbled in Notification Emails | Fixed an issue where notification emails did not use UTF-8 encoding, garbling non-ASCII characters. |
| 724691 | Misleading HTTP Strict Transport Security Notice on the Security Hardening Report | Fixed an issue where the wording of the Using HTTP strict transport security notice did not match the values it describes. |
| 724784 | Event Pipelines Task Modal Did Not Reopen After Cancel | Fixed an issue where the Event Pipelines task modal did not reopen when the plus button was clicked again after the modal was dismissed with Cancel. |
| 724912 | Secret Audit Tab Lost Heartbeat History in Large Environments | Fixed an issue where the Secret Audit tab lost recent heartbeat entries after the periodic maintenance job ran in high-volume environments. |
| 725086 | SAML Login Failed When Auto-Redirect Sent a Null ACS URL | Fixed an edge case where the SAML SSO ACS URL parameter could be sent as null to an unconfigured identity provider, causing login to fail. |
| 726276 | Secure Access Manual Retry Did Not Change Step Status From Error | Fixed an issue where re-running the Secure Access step after an error left the status unchanged. It now changes to In Progress. |
| 726303 | Uploading an Updated Password Dictionary Created a Duplicate | Fixed an issue where uploading a new version of a custom password dictionary file created a second dictionary instead of replacing the existing one. |
| 726783 | Platform Authentication Failed When the Signed-In User Had Been Deleted | Fixed an issue where Platform authentication errored when the signed-in user had been deleted. |
| 726855 | SAML Identity Providers Grid Remained Visible During Configuration Search | Fixed an issue where the SAML Identity Providers grid remained on screen for several seconds after searching on the Search configuration page. |
| 727375 | Search Filter Did Not Apply in the Add Role Permissions Modal | Fixed an issue where the search filter did not apply as you type when adding permissions to a role. |
| 727786 | Ticket Override Status Email Listed the Wrong Requestor | Fixed an issue where the email sent for a ticket override status change listed the wrong requestor. |
| 727938 | Force Check In Did Not Close the Displaced User's Launcher Session | Fixed an issue where Force Check In did not terminate the active launcher session of the user being displaced. |
| 728244 | Identity Providers Title Was Inconsistent Between Configuration Search and Settings | Fixed an issue where Identity providers did not appear as SAML identity providers in Search configuration, unlike its label elsewhere in the application. |
| 728271 | Extra Word in the Ticket Override Status Update Message | Fixed an issue where the Ticket Override status update message contained an extra word. |
| 728552 | Session Terminate Button Returned an Error | Fixed an issue where the Terminate button on live sessions returned an error. |
| 729027 | Add Groups Dialog Closed Silently With No Group Selected | Fixed an issue where the Add button in the Add groups dialog was enabled before a group was selected. |
| 729253 | Suggested Secrets Was Blank for Assets With Many Launches | Fixed an issue that could cause Suggested Secrets on Inventory > Computer to return nothing when launching to an asset with a secret. |
| 729354 | Session Recording Conversion Failed When Cleanup Ran Mid-Conversion | Fixed a race condition where the cleanup job could remove a recording's storage container while the video was still being assembled, leaving a completed recording marked with an error status. |
| 729564 | Secret Template Password Type Endpoint Returned a 500 Error | Fixed an issue where GET /api/v1/secret-templates/{id}/password-type failed with a 500 error when the template has no password type. |
| 729831 | Remote Password Changing Failed With a Null Reference Error During Secret Updates | Fixed an issue where remote password changing failed with a null reference error when a secret is updated. |
| 731307 | Entity Type and Event Time Labels Were Not Localized in Event Subscription Emails | Fixed an issue where the Entity type and Event time labels in event subscription notification emails did not render in the recipient's configured language. Affected languages were Japanese, German, French, Korean, Portuguese, Chinese Traditional, and Chinese Simplified. |
| 731322 | External Vault Link Without a Type Exposed a Raw Backend Error | Fixed an issue where external vault link creation submitted an invalid request and showed a raw deserializer error. The Type field is now validated. |
| 731342 | Disaster Recovery Folder Selection Displayed Language Resource Not Found | Fixed an issue where the Disaster Recovery folder selection dropdown displayed a missing locale key message instead of All folders as the first option. |
| 731386 | Disaster Recovery Handshakes Failed When a Proxy Stripped the Response Reason Phrase | Fixed an issue where Disaster Recovery handshakes failed when an intermediate proxy removed the HTTP response reason phrase. |
| 731407 | Applying a Secret Policy With Checkout Enabled Returned a 500 Error | Fixed an issue where applying a secret policy with Check Out enabled through PATCH /api/v1/secrets/{id}/general or its v2 equivalent returned an HTTP 500 API_SecretRequiresCheckout error even though the policy change had already been applied. It now returns a 200 success response. |
| 731999 | Launcher Window Size Accepted Empty and Decimal Values | Fixed an issue where the launcher window size fields in User Preferences accepted empty or decimal entries. |
| 732396 | Platform Webhooks Did Not Report All Expected Events | Fixed an issue where audit events from system-originated actions such as heartbeats, remote password changing, and scheduled tasks, along with audit events from local Secret Server users without email addresses, did not reach Delinea Platform Insights. Audit event details now show secret names rather than IDs and correctly populate the target user for events where a user is modified. |
| 732402 | Credential Manager Showed Business Users the IT Users' Secret Templates | Fixed an issue where business users saw secret templates their license does not include. |
| 732809 | RDP Proxy Sessions Failed in Dual-Stack IP Environments | Fixed an issue where the RDP Proxy could not connect to a target whose hostname resolves to IPv6 addresses. |
| 734136 | Outdated Link on the Advanced Configuration Page | On-premises only. Fixed an issue where an outdated Thycotic URL appeared on the Advanced Configuration page. |
| 735142 | RDP Proxy Endpoints Tab Could Not Be Saved or Disabled | Fixed an issue where RDP Proxy endpoints could not be saved or disabled when the RD Gateway port was left at its default of 0, with no option in cloud to set a default. The global RD Gateway port now defaults to 8443, saving and disabling no longer block on an inherited or unset port, and a site's Enable RDP Gateway setting is editable from the Endpoints page. |
| 743353 | Cryptographic Weakness in Pre-Authentication Sign-In Features | Fixed a weakness in the cryptographic protection of pre-authentication sign-in features, including the on-screen keyboard. |
| 743573 | SAML Authentication Bypass Through Assertion Signature Wrapping | Fixed an issue in SAML assertion signature validation that permitted an authentication bypass. |
| 745223 | Legacy CRYSTALS-Kyber QuantumLock Secrets Unreadable After Upgrade | Fixed an issue where secrets protected with the experimental CRYSTALS-Kyber QuantumLock implementation in Secret Server 11.8 through 11.10 became unreadable after upgrading to the finalized ML-KEM standard in 12.0 and later. These secrets are now recovered automatically the next time they are viewed. |
| 751354 | FIDO2 Two-Factor Registration Validation and Enrollment Reliability | Fixed several defects in the FIDO2 two-factor registration callback: validation has been hardened, the challenge comparison corrected, the one-time registration key lifetime extended so enrollment no longer times out prematurely, and failed-attempt accounting and logging corrected. |
Related Resources
Supporting documentation for this release: knowledge base articles, upgrade guidance, and security advisories.