CVE-2026-47158: Dani-Garcia Vaultwarden

High severity, CVSS 8.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left SsoAuth records intact after failed token exchange, allowing an unauthenticated attacker to induce IdP authentication and redeem tokens for a fully authenticated session. This issue is fixed in version 1.36.0.

Affected products

  • Dani-Garcia Vaultwarden: before 1.36.0 (fixed in 1.36.0)

Published 2026-07-15. Last modified 2026-07-15.