CVE-2026-47158

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left SsoAuth records intact after failed token exchange, allowing an unauthenticated attacker to induce IdP authentication and redeem tokens for a fully authenticated session. This issue is fixed in version 1.36.0.
Configurations

No configuration.

History

15 Jul 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 16:16

Updated : 2026-07-15 19:17


NVD link : CVE-2026-47158

Mitre link : CVE-2026-47158

CVE.ORG link : CVE-2026-47158


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)