logo

Vaultwarden Vulnerabilities Enable Privilege Escalation and Data Exposure

ID: b19a0726-fa81-5571-98d9-e60b1b7c17e4

STIX ID: report--b19a0726-fa81-5571-98d9-e60b1b7c17e4

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-09

Date Updated: 2026-07-21

Author: Divya

...
...

Two high-severity authorization vulnerabilities (CVE-2026-27803 and CVE-2026-27802) were disclosed in Vaultwarden 1.35.3: one permits Manager accounts to bypass collection management restrictions and perform administrative actions despite manage=false, and the other allows privilege escalation via the bulk-access API to gain access_all privileges. Both are network-exploitable with low complexity and no user interaction; administrators are urged to upgrade to Vaultwarden 1.35.4 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.