cbcvebase.

Dani-Garcia Vaultwarden vulnerabilities

25 known vulnerabilities affecting dani-garcia/vaultwarden.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH12MEDIUM10

Vulnerabilities

Page 1 of 2
CVE-2024-39924P2HIGHCVSS 8.8v1.30.32024-09-13
CVE-2024-39924 [HIGH] CWE-276 CVE-2024-39924: An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been iden An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an attacker with granted emergency access to escalate their privileges by changing the access level and modif
nvd
CVE-2026-43914P2CRITICALCVSS 9.8fixed in 1.35.42026-05-11
CVE-2026-43914 [CRITICAL] CWE-307 CVE-2026-43914: Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security v Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is enabled. If email 2fa is enabled, the unprotected 2fa-function send_email_login (email.rs, api endpoint /api/two-factor/send-email-login) also acts as
nvd
CVE-2024-55225P3CRITICALCVSS 9.8fixed in 1.32.52025-01-09
CVE-2024-55225 [CRITICAL] CWE-276 CVE-2024-55225: An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to im An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.
ghsanvdosv
CVE-2026-43912P3HIGHCVSS 8.7fixed in 1.35.52026-05-11
CVE-2026-43912 [HIGH] CWE-285 CVE-2026-43912: Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as groups.groups_uuid, or a collections_groups.collections_uuid entry belongs to the same organization as collections_groups.groups_uuid. Multiple organization gr
nvd
CVE-2026-95814P3HIGHCVSS 8.1≤ 1.37.32026-09-22
CVE-2026-95814 [HIGH] CWE-863 CVE-2026-95814: Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access- Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization ciphers. Attackers with revoked or pending membership can exploit missing status filters in get_user_collections_acc
nvd
CVE-2026-27802P3HIGHCVSS 8.3fixed in 1.35.42026-03-04
CVE-2026-27802 [HIGH] CWE-269 CVE-2026-27802: Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarde Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized collections by Manager. This issue has been patched in version 1.35.4.
ghsanvdosv
CVE-2026-43911P3HIGHCVSS 8.1fixed in 1.35.52026-05-11
CVE-2026-43911 [HIGH] CWE-613 CVE-2026-43911: Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are no Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (password change, KDF change, key rotation, email change, org admin password reset, emergency access takeover). This allows an attacker holding a previously ob
nvd
CVE-2026-27803P3HIGHCVSS 8.3fixed in 1.35.42026-03-04
CVE-2026-27803 [HIGH] CWE-269 CVE-2026-27803: Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarde Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations as long as they have access to the collection. This issue has been patched in version 1.35.4.
ghsanvdosv
CVE-2026-43913P3HIGHCVSS 8.1fixed in 1.35.52026-05-11
CVE-2026-43913 [HIGH] CWE-863 CVE-2026-43913: Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The organization invite flow uses a two-step process: accepting an invite transitions membership from Invited to Accepted, and a separate confirmation by an existing owner upgrades
nvd
CVE-2026-47158P3HIGHCVSS 8.3fixed in 1.36.02026-07-15
CVE-2026-47158 [HIGH] CWE-352 CVE-2026-47158: Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO aut Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left SsoAuth records intact after failed token exchange, allowing an unauthenticate
nvd
CVE-2026-47164P3HIGHCVSS 7.7fixed in 1.36.02026-07-15
CVE-2026-47164 [HIGH] CWE-284 CVE-2026-47164: Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO log Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true linked an IdP identity to an existing local account, allowing an attacker-controlled IdP identity asserting a victim email address to bind
nvd
CVE-2024-56335P3HIGHCVSS 7.5fixed in 1.32.72024-12-20
CVE-2024-56335 [HIGH] CWE-269 CVE-2024-56335: vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarde vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few conditions: 1. The attacker has a user account in the server. 2. The attacker's account has admin or owner permissions in an unrelated orga
nvd
CVE-2025-24364P3HIGHCVSS 7.2fixed in 1.33.02025-01-27
CVE-2025-24364 [HIGH] CWE-74 CVE-2025-24364: vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarde vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker with authenticated access to the vaultwarden admin panel can execute arbitrary code in the system. The attacker could then change some settings to use sendmail as mail agent but adjust the settings in such a way that it would use a shell c
nvd
CVE-2024-55224P3CRITICALCVSS 9.6fixed in 1.32.52025-01-09
CVE-2024-55224 [CRITICAL] CWE-79 CVE-2024-55224: An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrar An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.
ghsanvdosv
CVE-2025-24365P3HIGHCVSS 7.5fixed in 1.33.02025-01-27
CVE-2025-24365 [HIGH] CWE-284 CVE-2025-24365: vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarde vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real case the user can be a part of the organization as an unprivileged user) and be the owner/admin of other organization (by default you
nvd
CVE-2026-47159P3MEDIUMCVSS 6.9fixed in 1.36.02026-07-15
CVE-2026-47159 [MEDIUM] CWE-287 CVE-2026-47159: Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO dis Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation JWT to be obtained with only the discovered identifier, enabling SSO-ena
nvd
CVE-2026-26012P3MEDIUMCVSS 6.5fixed in 1.35.32026-02-11
CVE-2026-26012 [MEDIUM] CWE-863 CVE-2026-26012: vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarde vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35.3, a regular organization member can retrieve all ciphers within an organization, regardless of collection permissions. The endpoint /ciphers/organization-details is accessible to any organization member and internally uses Cipher:
nvd
CVE-2026-27801P3MEDIUMCVSS 5.9fixed in 1.35.02026-03-04
CVE-2026-27801 [MEDIUM] CWE-307 CVE-2026-27801: Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarde Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authenticated access to a user’s account can exploit this bypass to perform protected actions such as accessing the us
ghsanvdosv
CVE-2024-39925P3MEDIUMCVSS 6.5v1.30.32024-09-13
CVE-2024-39925 [MEDIUM] CWE-200 CVE-2024-39925: An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding proce An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member departs. Consequently, the departing member, whose access should be revoked, retains a copy of the organization key. Additionally, the appl
nvd
CVE-2026-47160P4MEDIUMCVSS 5.8fixed in 1.36.02026-07-15
CVE-2026-47160 [MEDIUM] CWE-918 CVE-2026-47160: Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/ Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_block_address() and post_resolve() that missed decimal, hexadecimal, and octal IP representations, allowing SSRF through the icon-fetching HTTP client for blind internal networ
nvd
Dani-Garcia Vaultwarden vulnerabilities | cvebase