CVE-2026-47158
Vaultwarden: CSRF in SSO Authorization Flow
Description
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left SsoAuth records intact after failed token exchange, allowing an unauthenticated attacker to induce IdP authentication and redeem tokens for a fully authenticated session. This issue is fixed in version 1.36.0.
In plain language
AI Worth attentionCVE-2026-47158 is a CSRF weakness in Vaultwarden’s SSO login flow that could let an attacker trick a user into completing an SSO login as the attacker, so businesses using SSO with Vaultwarden should upgrade to 1.36.0 or later.
In Vaultwarden, a CSRF issue in the SSO authorization flow (CWE-352) allowed the server to accept OAuth authorization inputs without properly binding the OAuth “state” to the initiating browser session and mishandled SSO authorization records during failed token exchange; this could let an unauthenticated attacker induce IdP authentication and redeem tokens for a fully authenticated session.
What to do now
- Check whether your Vaultwarden is using SSO (for example, any configured “connect/authorize” style SSO integration) and confirm your current Vaultwarden version.
- If you are running a Vaultwarden version prior to 1.36.0, plan an urgent upgrade.
- Upgrade Vaultwarden to 1.36.0 or later and restart the service.
- After upgrading, verify SSO logins still work normally and review authentication logs for unusual SSO/login patterns around the same time window as any suspicious activity.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:LConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-47158 and every CVE in our database. Create a free account — no credit card required.
Create Free Account