CVE-2026-32310 impacts Cryptomator versions 1.6.0 through 1.19.0, stemming from improper vault configuration parsing that allows unverified `keyId` values to be used as filesystem paths. This enables attackers to craft malicious vault configurations that can trigger directory traversal, absolute local paths, or UNC paths. On Windows, this is particularly dangerous as it can force outbound SMB connections, potentially leading to NTLM hash leakage, even before a user enters a passphrase. This medium-severity vulnerability (CVSS 5.3) has a network attack vector and low complexity, primarily posing a confidentiality risk. There is currently no evidence of active exploitation, public exploit code, or significant community attention for this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.6.0, <= 1.19.0CPE matchmatch criteria | cpe:2.3:a:cryptomator:cryptomator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.