CVE-2021-36758: Input Validation

Published Jul 15, 2021
·
Updated

1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Malicious users authorized to create Secrets Automation access tokens can create tokens that have access beyond what the user is authorized to access, but limited to the existing authorizations of the Secret Automation the token is created in.

Affected Software

1 affected component
1Password connect<1.2

Event History

Jul 15, 2021
CVE Published
via MITRE·11:14 PM
Data Sourced
via MITRE·11:14 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2021-36758?

CVE-2021-36758 is considered a high severity vulnerability due to the potential for privilege escalation through unauthorized access tokens.

2

How do I fix CVE-2021-36758?

To fix CVE-2021-36758, update your 1Password Connect server to version 1.2 or later.

3

Who is affected by CVE-2021-36758?

CVE-2021-36758 affects users of the 1Password Connect server version prior to 1.2.

4

What are the consequences of CVE-2021-36758?

The consequences of CVE-2021-36758 include the potential for unauthorized users to create access tokens that allow privilege escalation.

5

Is there a workaround for CVE-2021-36758?

There is no specific workaround for CVE-2021-36758; the only resolution is to upgrade to a patched version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203