Improper restriction of communication channel to intended endpoints in Cryptomator - CVE-2026-32303
Published: April 20, 2026
Cryptomator
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper restriction of communication channel to intended endpoints in the Hub key loading mechanism when processing a tampered vault configuration file during unlock. A remote user can alter the vault.cryptomator file to disclose sensitive information.
User interaction is required to unlock a Hub-backed vault, and vault data was not exposed because Cryptomator Hub uses end-to-end encryption.