CVE-2026-43914
- EPSS 0.29%
- Veröffentlicht 11.05.2026 22:03:58
- Zuletzt bearbeitet 13.05.2026 19:35:51
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is enabled. If email 2fa is enabled, the unprotected 2...
CVE-2026-43913
- EPSS 0.27%
- Veröffentlicht 11.05.2026 22:01:35
- Zuletzt bearbeitet 13.05.2026 19:29:54
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The organization invite flow uses a two-step process: accepting an invite tran...
CVE-2026-43912
- EPSS 0.29%
- Veröffentlicht 11.05.2026 21:56:30
- Zuletzt bearbeitet 15.05.2026 20:19:43
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as groups.groups_uuid, or a collections_groups.collections...
CVE-2026-43911
- EPSS 0.22%
- Veröffentlicht 11.05.2026 21:54:41
- Zuletzt bearbeitet 18.05.2026 16:58:20
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (password change, KDF change, key rotation, email change...
CVE-2026-33420
- EPSS 0.17%
- Veröffentlicht 05.05.2026 20:16:36
- Zuletzt bearbeitet 08.05.2026 19:19:39
Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing the has_full_access() authorization check that exis...
CVE-2026-31835
- EPSS 0.15%
- Veröffentlicht 05.05.2026 18:51:35
- Zuletzt bearbeitet 11.05.2026 16:59:34
Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authentication flow in `validate_webauthn_login()` updates persistent credential metadata (1backup_eligible1 and 1backup_state flags1) based on...
CVE-2026-27898
- EPSS 0.17%
- Veröffentlicht 04.03.2026 21:44:45
- Zuletzt bearbeitet 06.03.2026 19:45:12
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial" Even though...
CVE-2026-27803
- EPSS 0.29%
- Veröffentlicht 04.03.2026 21:40:33
- Zuletzt bearbeitet 06.03.2026 19:45:27
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations as long as...
CVE-2026-27802
- EPSS 0.29%
- Veröffentlicht 04.03.2026 21:34:34
- Zuletzt bearbeitet 06.03.2026 19:45:31
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized collections by Manager. This i...
CVE-2026-27801
- EPSS 0.26%
- Veröffentlicht 04.03.2026 21:32:14
- Zuletzt bearbeitet 06.03.2026 19:45:34
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authenticated acc...