SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-47159

MEDIUM · CVSS 6.9 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Vaultwarden versions prior to 1.36.0 are vulnerable to a security flaw that allows unauthorized users to enumerate organizations and abuse the authentication workflow by obtaining valid pre-validation JWTs using arbitrary email addresses. This could lead to unauthorized access to sensitive organization-related information. Organizations using Vaultwarden should prioritize upgrading to version 1.36.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-47159
Severity
MEDIUM
CVSS
6.9
EPSS
0.37%

Original NVD Description

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation JWT to be obtained with only the discovered identifier, enabling SSO-enabled organization enumeration and authentication workflow abuse. This issue is fixed in version 1.36.0.