Vaultwarden是Daniel García个人开发者的一个用 Rust 编写的 Bitwarden 服务器 API 的替代实现。 Vaultwarden 1.35.5之前版本存在安全漏洞,该漏洞源于允许未确认的组织所有者清除整个组织保险库,组织邀请流程使用两步过程,POST /api/ciphers/purge端点仅检查成员类型为所有者而不验证成员状态为已确认,已受邀为组织所有者并已接受邀请但尚未被确认的认证用户可调用此端点硬删除组织中的所有密码和附件,导致立即的组织范围数据丢失。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dani-garcia | vaultwarden | < 1.35.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dani-garcia | vaultwarden | < 1.35.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43912 | 8.7 HIGH | Vaultwarden: Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Anoth |
| CVE-2026-43914 | 7.3 HIGH | Vaultwarden: Brute-force protection bypass vulnerability |
| CVE-2026-43911 | 6.8 MEDIUM | Vaultwarden: Refresh tokens not invalidated on security stamp rotation |
No comments yet