CVE-2026-47159: Vaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token Exposure
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation JWT to be obtained with only the discovered identifier, enabling SSO-enabled organization enumeration and authentication workflow abuse. This issue is fixed in version 1.36.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Vaultwardento a version that resolves this vulnerability.Fixed in 1.36.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47159?
CVE-2026-47159 has a medium severity rating of 6.9.
What does CVE-2026-47159 affect?
CVE-2026-47159 affects Vaultwarden, a Bitwarden-compatible server.
How do I fix CVE-2026-47159?
To fix CVE-2026-47159, upgrade Vaultwarden to version 1.36.0 or later.
What kind of vulnerability is CVE-2026-47159?
CVE-2026-47159 is an authentication flow information disclosure vulnerability.
What are the potential impacts of CVE-2026-47159?
CVE-2026-47159 can lead to organization enumeration and pre-validation token exposure.