CVE-2026-32303Disclosure(cryptomator / cryptomator)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted endpoints from the vault config without host authenticity checks, which could allow token exfiltration by mixing a legitimate auth endpoint with a malicious API endpoint. Impacted are users unlocking Hub-backed vaults with affected client versions in environments where an attacker can alter the vault.cryptomator file. This issue has been patched in version 1.19.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346CWE-354CWE-451CWE-923

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cryptomator

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
cryptomator

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-22: 1Mentions · 2026-03-26: 1Technical Details · 2026-03-22: 103-2203-26
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-221
Disclosure1
2026-03-261
General1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32303 Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault … https://www.cve.org/CVERecord?id=CVE-2026-32303

    Post summary

    An integrity‑check flaw in Cryptomator prior to version 1.19.1 allows attackers to tamper with vault data stored on cloud infrastructure.

    01010143
    56.8K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-32303: Cryptomator Vault Configuration Bug - What It Means for Your Business and How to Respond https://hubs.li/Q048t7BC0

    Post summary

    The fragment only lists the CVE id and a title, offering no information on proof‑of‑concepts, exploitation, or patches.

    0000031
    29 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcryptomatorcryptomator---

Explore more