CVE-2026-26012
- EPSS 0.33%
- Veröffentlicht 11.02.2026 21:14:58
- Zuletzt bearbeitet 13.02.2026 21:41:01
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35.3, a regular organization member can retrieve all ciphers within an organization, regardless of collection permissions. The endpoi...
CVE-2025-24365
- EPSS 0.65%
- Veröffentlicht 27.01.2025 18:15:41
- Zuletzt bearbeitet 20.08.2025 13:56:46
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real case the user can be a part of...
CVE-2025-24364
- EPSS 0.96%
- Veröffentlicht 27.01.2025 18:15:41
- Zuletzt bearbeitet 20.08.2025 14:16:53
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker with authenticated access to the vaultwarden admin panel can execute arbitrary code in the system. The attacker could then change some ...
CVE-2024-56335
- EPSS 0.33%
- Veröffentlicht 20.12.2024 21:15:10
- Zuletzt bearbeitet 19.08.2025 13:46:58
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few conditions: 1. The attacker has a us...
CVE-2024-39926
- EPSS 0.43%
- Veröffentlicht 13.09.2024 18:15:04
- Zuletzt bearbeitet 10.07.2025 13:22:41
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This potentially allows an authenticated a...
CVE-2024-39924
- EPSS 13.06%
- Veröffentlicht 13.09.2024 18:15:03
- Zuletzt bearbeitet 10.07.2025 13:23:50
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an att...
CVE-2024-39925
- EPSS 0.57%
- Veröffentlicht 13.09.2024 18:15:03
- Zuletzt bearbeitet 10.07.2025 13:23:03
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member departs. Consequently, the departing m...