CVE-2026-33472Disclosure(cryptomator / cryptomator)

LOWCVSS 4.8 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw in CheckHostTrustController.getAuthority() that allows an attacker to bypass the security fix for CVE-2026-32303. The method hardcodes the URI scheme based on port number, causing HTTPS URLs with port 80 to produce the same authority string as HTTP URLs, which defeats both the consistency check and the HTTP block validation. An attacker with write access to a cloud-synced vault.cryptomator file can craft a Hub configuration where apiBaseUrl and authEndpoint use HTTPS with port 80 to pass auto-trust validation, while tokenEndpoint uses plaintext HTTP. The vault is auto-trusted without user prompt, and a network-positioned attacker can intercept the OAuth token exchange to access the Cryptomator Hub API as the victim. This issue has been fixed in version 1.19.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-305CWE-319

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cryptomator

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
cryptomator

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-17: 2Technical Details · 2026-04-17: 204-17
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33472 Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw in CheckHostTrustController.getAuthority() th… https://www.cve.org/CVERecord?id=CVE-2026-33472

    Post summary

    A logic flaw in Cryptomator v1.19.1’s CheckHostTrustController.getAuthority() method was disclosed as CVE‑2026‑33472.

    0000075
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33472 Security Bypass in Cryptomator 1.19.1 via Port-Based URI Scheme Logic Flaw https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33472

    Post summary

    A CVE for a security bypass in Cryptomator 1.19.1 is listed with a brief technical description, but no active exploitation, patch, or proof‑of‑concept details are provided.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcryptomatorcryptomator---

Explore more