Vaultwarden是Daniel García个人开发者的一个用 Rust 编写的 Bitwarden 服务器 API 的替代实现。 Vaultwarden 1.34.3及之前版本存在安全漏洞,该漏洞源于执行受保护操作时可绕过双因素认证,可能导致获得账户认证访问权限的攻击者执行如访问用户API密钥或删除用户保险库等受保护操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dani-garcia | vaultwarden | < 1.35.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27802 | 8.3 HIGH | Vaultwarden: Privilege Escalation via Bulk Permission Update to Unauthorized Collections b |
| CVE-2026-27803 | 8.3 HIGH | Vaultwarden: Collection Management Operations Allowed Without `manage` Verification for Ma |
| CVE-2026-27898 | 5.4 MEDIUM | Vaultwarden: Unauthorized Access via Partial Update API on Another User’s Cipher |
No comments yet