Vaultwarden是Daniel García个人开发者的一个用 Rust 编写的 Bitwarden 服务器 API 的替代实现。 Vaultwarden 1.35.4之前版本存在安全漏洞,该漏洞源于Manager对特定集合manage=false时仍可执行多项管理操作,可能导致权限问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dani-garcia | vaultwarden | < 1.35.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27802 | 8.3 HIGH | Vaultwarden: Privilege Escalation via Bulk Permission Update to Unauthorized Collections b |
| CVE-2026-27898 | 5.4 MEDIUM | Vaultwarden: Unauthorized Access via Partial Update API on Another User’s Cipher |
| CVE-2026-27801 | Vaultwarden: 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement |
No comments yet