Vaultwarden是Daniel García个人开发者的一个用 Rust 编写的 Bitwarden 服务器 API 的替代实现。 Vaultwarden 1.35.4之前版本存在安全漏洞,该漏洞源于经过身份验证的普通用户可指定其他用户的cipher_id并调用部分更新端点,可能导致暴露密文详细信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dani-garcia | vaultwarden | < 1.35.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27802 | 8.3 HIGH | Vaultwarden: Privilege Escalation via Bulk Permission Update to Unauthorized Collections b |
| CVE-2026-27803 | 8.3 HIGH | Vaultwarden: Collection Management Operations Allowed Without `manage` Verification for Ma |
| CVE-2026-27801 | Vaultwarden: 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement |
No comments yet