Cryptomator is a focused file-encryption utility designed to protect data at rest in cloud storage, where its vulnerability profile centers on a single product but carries significance due to the sensitivity of the cryptographic and storage-integrity functions it provides. The recurring weaknesses—including improper restriction of communication channels, integrity-check validation issues, origin validation errors, UI misrepresentation of security-critical information, and cleartext transmission of sensitive data—reflect the challenges of maintaining cryptographic assurance and user awareness in a client-side encryption tool. Defenders should track this vendor's releases closely given the security-sensitive nature of its product, even within a modest disclosure volume; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cryptomator over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32309HIGH Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and consumes Hub endpoints from vaul | Mar 20, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-32303MEDIUM Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration | Mar 20, 2026 | 5.9 | 23 | NO | NO |
CVE-2026-32318MEDIUM Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tam | Mar 20, 2026 | 5.9 | 22 | NO | NO |
CVE-2026-32317MEDIUM Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 1.12.3, an integrity check vulnerability allows an attacke | Mar 20, 2026 | 5.9 | 22 | NO | NO |
CVE-2023-39520HIGH Cryptomator encrypts data being stored on cloud infrastructure. The MSI installer provided on the homepage for Cryptomator version 1.9.2 allows local privilege escalation for low p | Aug 7, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-37907HIGH Cryptomator is data encryption software for users who store their files in the cloud. Prior to version 1.9.2, the MSI installer provided on the homepage allows local privilege esca | Jul 25, 2023 | 7.8 | 21 | NO | NO |
CVE-2026-32310MEDIUM Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault configuration is parsed before its integrity is verified, and the | Mar 20, 2026 | 5.3 | 20 | NO | NO |
CVE-2022-25366HIGH Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has the com.apple.security.cs.disable-library-validation and com. | Feb 19, 2022 | 7.8 | 20 | NO | NO |
CVE-2026-33472MEDIUM Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw in CheckHostTrustController.getAuthority() that allows an a | Apr 16, 2026 | 4.8 | 19 | NO | NO |
CVE-2026-29110MEDIUM Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.0, in non-debug mode Cryptomator might leak cleartext paths into the log file. This can reveal | Mar 6, 2026 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cryptomator.
Media articles that mention a CVE ID that affects a product developed by Cryptomator — matched by CVE ID, not by vendor name.