PT-2026-33365 · Unknown · Cryptomator

Published

2026-04-16

·

Updated

2026-04-17

·

CVE-2026-33472

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cryptomator version 1.19.1
Description A logic flaw exists in the getAuthority() function of the CheckHostTrustController. The method hardcodes the URI scheme based on the port number, which results in HTTPS URLs using port 80 producing the same authority string as HTTP URLs. This bypasses the consistency check and HTTP block validation. An attacker with write access to a cloud-synced vault.cryptomator file can configure the apiBaseUrl and authEndpoint variables to use HTTPS with port 80 to pass auto-trust validation, while the tokenEndpoint variable uses plaintext HTTP. This allows the vault to be auto-trusted without a user prompt, enabling a network-positioned attacker to intercept the OAuth token exchange and access the Cryptomator Hub API as the victim.
Recommendations Update to version 1.19.2.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2026-33472

Affected Products

Cryptomator