CVE-2026-47158: CWE-352: Cross-Site Request Forgery (CSRF) in dani-garcia vaultwarden
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left SsoAuth records intact after failed token exchange, allowing an unauthenticated attacker to induce IdP authentication and redeem tokens for a fully authenticated session. This issue is fixed in version 1.36.0.
AI Analysis
Technical Summary
Vaultwarden, a Bitwarden-compatible server written in Rust, has a CSRF vulnerability (CWE-352) in its SSO authorization flow prior to version 1.36.0. The OAuth state parameter accepted by the /connect/authorize endpoint is not tied to the initiating browser session, and attacker-controlled PKCE parameters are allowed. Additionally, SsoAuth records are not cleared after failed token exchanges. These flaws enable an unauthenticated attacker to trigger IdP authentication and redeem tokens, effectively obtaining a fully authenticated session. The vulnerability has a CVSS 3.1 score of 8.3, indicating high severity, and is resolved in Vaultwarden 1.36.0.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to induce the Identity Provider authentication process and redeem tokens, resulting in unauthorized access to a fully authenticated session. This compromises confidentiality, integrity, and availability of the affected Vaultwarden server.
Mitigation Recommendations
This vulnerability is fixed in Vaultwarden version 1.36.0. Users should upgrade to version 1.36.0 or later to remediate this issue. Patch status is not explicitly confirmed in the vendor advisory, but the description states the issue is fixed in 1.36.0, indicating an official fix is available.
CVE-2026-47158: CWE-352: Cross-Site Request Forgery (CSRF) in dani-garcia vaultwarden
Description
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left SsoAuth records intact after failed token exchange, allowing an unauthenticated attacker to induce IdP authentication and redeem tokens for a fully authenticated session. This issue is fixed in version 1.36.0.
CVSS v3.1
Score 8.3high
Affected software
pkg:cargo/github/dani-garcia/vaultwardenRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Vaultwarden, a Bitwarden-compatible server written in Rust, has a CSRF vulnerability (CWE-352) in its SSO authorization flow prior to version 1.36.0. The OAuth state parameter accepted by the /connect/authorize endpoint is not tied to the initiating browser session, and attacker-controlled PKCE parameters are allowed. Additionally, SsoAuth records are not cleared after failed token exchanges. These flaws enable an unauthenticated attacker to trigger IdP authentication and redeem tokens, effectively obtaining a fully authenticated session. The vulnerability has a CVSS 3.1 score of 8.3, indicating high severity, and is resolved in Vaultwarden 1.36.0.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to induce the Identity Provider authentication process and redeem tokens, resulting in unauthorized access to a fully authenticated session. This compromises confidentiality, integrity, and availability of the affected Vaultwarden server.
Mitigation Recommendations
This vulnerability is fixed in Vaultwarden version 1.36.0. Users should upgrade to version 1.36.0 or later to remediate this issue. Patch status is not explicitly confirmed in the vendor advisory, but the description states the issue is fixed in 1.36.0, indicating an official fix is available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-18T21:25:34.496Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a57a83f68715ace43f80be4
Added to database: 07/15/2026, 15:33:19 UTC
Last enriched: 07/15/2026, 15:48:51 UTC
Last updated: 08/26/2026, 22:52:11 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.