CVE-2026-47159
NONE—CVSS v3
—CVSS v2
0.37%
EPSS (exploit probability)
CWE-287CWE
Description
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation JWT to be obtained with only the discovered identifier, enabling SSO-enabled organization enumeration and authentication workflow abuse. This issue is fixed in version 1.36.0.
Affected routers (0)
No routers currently mapped to this CVE in our database.