CVE-2026-32309 impacts Cryptomator versions prior to 1.19.1, allowing the Hub-based unlock flow to transmit sensitive OAuth and key-loading traffic over unencrypted HTTP. This vulnerability enables an active network attacker to intercept or tamper with bearer tokens and endpoint-level trust decisions, resulting in a high confidentiality impact. Rated 7.5 HIGH on CVSS, it has a low attack complexity and requires no user interaction. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion regarding this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.19.1CPE matchmatch criteria | cpe:2.3:a:cryptomator:cryptomator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.