Junglewise Threat Intelligence

CVE-2026-47158: Vaultwarden CSRF and session hijacking in SSO authorization flow

CVE-2026-47158 · Severity: high · CVSS 8.3 · Published 2026-07-15

Technologies: Dani-Garcia Vaultwarden. Vendors: Dani-Garcia.

Executive brief

Vaultwarden, an open-source password management server, contained a security flaw in its Single Sign-On (SSO) login process. An attacker could trick a user into a malicious login flow that allows the attacker to hijack the session and gain access to the user's encrypted vault data. This could lead to the exposure of sensitive passwords and credentials stored within the organization.

Technical details

A vulnerability in Vaultwarden's SSO implementation (prior to version 1.36.0) stems from a failure to bind the OAuth 'state' parameter accepted by the /connect/authorize endpoint to the initiating browser session. Additionally, the application allowed attacker-controlled PKCE parameters and failed to invalidate SsoAuth records after unsuccessful token exchanges. An unauthenticated remote attacker can exploit these weaknesses via a Cross-Site Request Forgery (CSRF) vector to induce Identity Provider (IdP) authentication and subsequently redeem tokens for a fully authenticated session. While the master password is still required for full decryption of some data, an attacker can successfully fetch encrypted vault data. The issue is resolved in version 1.36.0 by implementing cookie-based session binding for SSO tokens.

Affected products

  • dani-garcia Vaultwarden < 1.36.0

Timeline

  • 2026-04-29: patched: Fixes committed to main branch
  • 2026-05-03: advisory: Release 1.36.0 published with security fixes
  • 2026-07-15: disclosed: CVE-2026-47158 published

References