CVE-2026-32309General(cryptomator / cryptomator)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cryptomator cryptomator systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and consumes Hub endpoints from vault metadata without enforcing HTTPS. As a result, a vault configuration can drive OAuth and key-loading traffic over plaintext HTTP or other insecure endpoint combinations. An active network attacker can tamper with or observe this traffic. Even when the vault key is encrypted for the device, bearer tokens and endpoint-level trust decisions are still exposed to downgrade and interception. This issue has been patched in version 1.19.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-319

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cryptomator

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-27); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
cryptomator

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-22: 1Mentions · 2026-04-27: 2Mentions · 2026-04-28: 1Mentions · 2026-04-29: 1Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-29: 103-2204-2704-2804-29
Signal classification3 categories
General
240.0%
Disclosure
240.0%
Patch
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-221
Patch1
2026-04-272
General2
2026-04-281
Disclosure1
2026-04-291
Disclosure1
Full discourse5 posts
  • yousukezan@yousukezan
    General

    「脆弱性の指摘であればトリアージまでの時間がOSSのPRより早く、ついでにセキュリティの勉強にもなるし、しかも非公開で報告できる(=公開 Issue と違って失敗しても外から見えない)ぞ」 春休みなので脆弱性報告したらCVEついた話 (CVE-2026-32309)|Yanchon https://zenn.dev/ao9s/articles/cryptomator-hub-http-downgrade #zenn

    Post summary

    The author states that a vulnerability was privately reported and received a CVE assignment (CVE-2026-32309), but provides no technical details, exploit evidence, or remediation guidance.

    0141121587.8K
    14.4K followersView on X
  • Shota Zaizen (財前 匠汰)@z41zen
    General

    春休みなので脆弱性報告したらCVEついた話 (CVE-2026-32309)|Yanchon https://zenn.dev/ao9s/articles/cryptomator-hub-http-downgrade #zenn

    Post summary

    The snippet simply notes that a CVE (CVE-2026-32309) was assigned after a vulnerability report during spring break, with no further technical or operational details provided.

    0102251.3K
    47 followersView on X
  • topickapp (IT技術系ニュースサイト)@topickapp_com
    Disclosure

    https://zenn.dev/ao9s/articles/cryptomator-hub-http-downgrade 学生がCryptomatorの脆弱性(CVE-2026-32309)を発見し、CVEを取得した体験談です。 外部からの値の検証不足が原因で、HTTP通信へのダウングレード攻撃が可能でした。 報告から修正、CVE公開までの迅速な対応と、再現手順の重要性を解説しています。

    Post summary

    A student discovered a CVE‑2026‑32309 downgrade vulnerability in Cryptomator, highlighting quick patching and the importance of reproducibility steps, but the text does not provide a PoC or evidence of active exploitation.

    0000087
    665 followersView on X
  • Sigma/シグマ@sigma7863
    Disclosure

    春休みなので脆弱性報告したらCVEついた話 (CVE-2026-32309)|Yanchon https://zenn.dev/ao9s/articles/cryptomator-hub-http-downgrade #zenn

    Post summary

    A developer shares that they reported a vulnerability during spring break, resulting in a CVE assignment (CVE-2026-32309) related to Cryptomator Hub HTTP downgrade.

    0000040
    90 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-32309 Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and consumes Hub endpo… https://www.cve.org/CVERecord?id=CVE-2026-32309

    Post summary

    The entry references CVE-2026-32309 and notes that newer releases (post‑1.19.1) address the issue, but offers no further technical or exploit details.

    0000084
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcryptomatorcryptomator---

Explore more