CVE-2026-47158: Vaultwarden: CSRF in SSO Authorization Flow
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left SsoAuth records intact after failed token exchange, allowing an unauthenticated attacker to induce IdP authentication and redeem tokens for a fully authenticated session. This issue is fixed in version 1.36.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Vaultwardento a version that resolves this vulnerability.Fixed in 1.36.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47158?
The severity of CVE-2026-47158 is rated high with a score of 8.3.
What type of vulnerability is CVE-2026-47158?
CVE-2026-47158 is a Cross-Site Request Forgery (CSRF) vulnerability in the SSO Authorization Flow of Vaultwarden.
How do I fix CVE-2026-47158?
To fix CVE-2026-47158, upgrade Vaultwarden to version 1.36.0 or later, where this issue has been addressed.
What impact does CVE-2026-47158 have on my security?
CVE-2026-47158 allows attackers to exploit flaws in the SSO authorization flow, which can lead to unauthorized access and potential data compromise.
Is CVE-2026-47158 specific to any software version?
Yes, CVE-2026-47158 affects Vaultwarden prior to version 1.36.0.