CVE-2026-33472
- EPSS 0.01%
- Veröffentlicht 16.04.2026 21:12:37
- Zuletzt bearbeitet 17.04.2026 15:38:09
Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw in CheckHostTrustController.getAuthority() that allows an attacker to bypass the security fix for CVE-2026-32303. The method hard...
CVE-2026-32317
- EPSS 0.01%
- Veröffentlicht 20.03.2026 18:29:01
- Zuletzt bearbeitet 26.03.2026 13:56:28
Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 1.12.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-mid...
CVE-2026-32318
- EPSS 0.01%
- Veröffentlicht 20.03.2026 18:27:22
- Zuletzt bearbeitet 26.03.2026 13:48:30
Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle v...
CVE-2026-32310
- EPSS 0.03%
- Veröffentlicht 20.03.2026 18:19:30
- Zuletzt bearbeitet 25.03.2026 20:45:24
Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault configuration is parsed before its integrity is verified, and the masterkeyfile loader uses the unverified keyId as a filesystem path. ...
CVE-2026-32309
- EPSS 0.02%
- Veröffentlicht 20.03.2026 18:19:09
- Zuletzt bearbeitet 27.03.2026 16:16:24
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and consumes Hub endpoints from vault metadata without enforcing HTTPS. As a result, a vault configuration...
CVE-2026-32303
- EPSS 0.02%
- Veröffentlicht 20.03.2026 18:16:14
- Zuletzt bearbeitet 26.03.2026 13:55:14
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading m...
CVE-2026-29110
- EPSS 0.03%
- Veröffentlicht 06.03.2026 17:53:53
- Zuletzt bearbeitet 13.03.2026 18:58:03
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.0, in non-debug mode Cryptomator might leak cleartext paths into the log file. This can reveal meta information about the files stored inside a vault at a time, whe...
CVE-2023-39520
- EPSS 0.03%
- Veröffentlicht 07.08.2023 20:15:09
- Zuletzt bearbeitet 10.04.2025 20:53:51
Cryptomator encrypts data being stored on cloud infrastructure. The MSI installer provided on the homepage for Cryptomator version 1.9.2 allows local privilege escalation for low privileged users, via the `repair` function. The problem occurs as the ...
CVE-2023-37907
- EPSS 0.04%
- Veröffentlicht 25.07.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:12:26
Cryptomator is data encryption software for users who store their files in the cloud. Prior to version 1.9.2, the MSI installer provided on the homepage allows local privilege escalation (LPE) for low privileged users, if already installed. The probl...
CVE-2022-25366
- EPSS 0.06%
- Veröffentlicht 19.02.2022 03:15:14
- Zuletzt bearbeitet 21.11.2024 06:52:05
Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has the com.apple.security.cs.disable-library-validation and com.apple.security.cs.allow-dyld-environment-variables entitlements. An at...