CVE-2026-47159 Details
Description
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation JWT to be obtained with only the discovered identifier, enabling SSO-enabled organization enumeration and authentication workflow abuse. This issue is fixed in version 1.36.0.
A vulnerability in Vaultwarden's SSO discovery and pre-validation process prior to version 1.36.0 enables organization enumeration and improper token validation. The issue arises because the SSO flow returns organization-related metadata, including identifiers for arbitrary email addresses, without verifying email ownership. This allows attackers to discover SSO-enabled organizations linked to specific emails and obtain pre-validation JWTs, potentially abusing the authentication workflow.
Users are advised to update Vaultwarden to version 1.36.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 15, 2026CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-hxqh-ff5p-wfr3 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/dani-garcia/vaultwarden/commit/d297e274a35dccd0f5d935e9d5934e0f7e9c0a87 | [email protected] | Source CodeVendor |
| https://github.com/dani-garcia/vaultwarden/pull/7163 | [email protected] | Source CodeVendor |
| https://github.com/dani-garcia/vaultwarden/releases/tag/1.36.0 | [email protected] | Release NotesVendor |
| https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-hxqh-ff5p-wfr3 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Vaultwarden | < 1.35.8 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | New CVE Received | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
Volerion