PT-2026-60202 · Unknown · Vaultwarden
CVE-2026-47159
·
Published
2026-07-15
·
Updated
2026-07-15
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vaultwarden versions prior to 1.36.0
Description
The SSO discovery and pre-validation flow returns organization-related SSO metadata, including
organizationIdentifier values, for arbitrary email addresses. This allows a valid pre-validation JWT (JSON Web Token, a compact, URL-safe means of representing claims to be transferred between two parties) to be obtained using only the discovered identifier, which enables the enumeration of SSO-enabled organizations and abuse of the authentication workflow.Recommendations
Update to version 1.36.0.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vaultwarden