CVE-2026-32309 Details
Description
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and consumes Hub endpoints from vault metadata without enforcing HTTPS. As a result, a vault configuration can drive OAuth and key-loading traffic over plaintext HTTP or other insecure endpoint combinations. An active network attacker can tamper with or observe this traffic. Even when the vault key is encrypted for the device, bearer tokens and endpoint-level trust decisions are still exposed to downgrade and interception. This issue has been patched in version 1.19.1.
A vulnerability exists in Cryptomator's Hub-based unlock flow prior to version 1.19.1, allowing vault configurations to direct OAuth and key-loading traffic over unencrypted HTTP or other insecure endpoints. This oversight enables active network attackers to intercept or manipulate this traffic. Even with encrypted vault keys, bearer tokens and endpoint trust decisions remain vulnerable to interception and downgrading.
Users should update to Cryptomator version 1.19.1 or later, which removes support for 'hub+http' in production builds and enforces HTTPS for all Hub endpoint values.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cryptomator/cryptomator/releases/tag/1.19.1 | [email protected] | Release Notes |
| https://github.com/cryptomator/cryptomator/security/advisories/GHSA-vv33-h7qx-c264 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cryptomator cryptomator | < 1.19.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 27, 2026 | CVE Modified | CISA-ADP |
| Mar 25, 2026 | Initial Analysis | [email protected] |
| Mar 25, 2026 | CVE Modified | CISA-ADP |
| Mar 20, 2026 | New CVE Received | [email protected] |