PT-2026-26655 · Unknown · Cryptomator

Published

2026-03-20

·

Updated

2026-03-26

·

CVE-2026-32303

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cryptomator versions prior to 1.19.1
Description Cryptomator encrypts data stored on cloud infrastructure. A flaw in integrity checks allows tampering with the vault configuration file, potentially leading to a man-in-the-middle issue during Hub key loading. Before version 1.19.1, the client trusted endpoints from the vault configuration without verifying host authenticity. This could allow an attacker to exfiltrate tokens by substituting a legitimate authentication endpoint with a malicious API endpoint. The issue impacts users unlocking Hub-backed vaults with vulnerable client versions in environments where an attacker can modify the vault.cryptomator file.
Recommendations Update to version 1.19.1 or later.

Exploit

Fix

UI Misrepresentation of Critical Information

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2026-32303
GHSA-34RF-RWR3-7G43

Affected Products

Cryptomator