Description
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation JWT to be obtained with only the discovered identifier, enabling SSO-enabled organization enumeration and authentication workflow abuse. This issue is fixed in version 1.36.0.
Published: 2026-07-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to version 1.36.0, its SSO discovery and pre-validation flow returned organization-related SSO metadata, including organizationIdentifier values, for arbitrary email addresses. This flow also allowed an attacker to obtain a valid pre-validation JWT using only the discovered identifier, enabling organization enumeration and abuse of the authentication workflow. The flaw is classified as CWE-287.

Affected Systems

The affected product is Vaultwarden published by dani-garcia. All releases older than 1.36.0 are vulnerable; the issue is fixed in 1.36.0 and later.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation. Vaultwarden is not listed in the CISA KEV catalog, so no public exploits have been recorded. The likely attack vector is remote, requiring network access to the SSO discovery endpoint; no privilege escalation or local access is required. Once the vulnerability is triggered, an attacker can enumerate all organizations that register email addresses with the service and then use the valid pre-validation JWT to impersonate users or gain access to protected resources.

Generated by OpenCVE AI on July 31, 2026 at 03:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Vaultwarden 1.36.0 or newer.
  • Restrict network access to the SSO discovery endpoint if an upgrade is delayed.
  • Review and revoke any pre-validation tokens that may have been exposed.

Generated by OpenCVE AI on July 31, 2026 at 03:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Dani-garcia
Dani-garcia vaultwarden
Vendors & Products Dani-garcia
Dani-garcia vaultwarden

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation JWT to be obtained with only the discovered identifier, enabling SSO-enabled organization enumeration and authentication workflow abuse. This issue is fixed in version 1.36.0.
Title Vaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token Exposure
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Dani-garcia Vaultwarden
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-15T15:34:11.312Z

Reserved: 2026-05-18T21:25:34.496Z

Link: CVE-2026-47159

cve-icon Vulnrichment

Updated: 2026-07-15T15:34:06.804Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:45:04Z

Weaknesses