Vaultwarden Vulnerabilities Enable Privilege Escalation and Data Exposure
ID: b19a0726-fa81-5571-98d9-e60b1b7c17e4
STIX ID: report--b19a0726-fa81-5571-98d9-e60b1b7c17e4
Feed Name: GBHackers
Two high-severity authorization vulnerabilities (CVE-2026-27803 and CVE-2026-27802) were disclosed in Vaultwarden 1.35.3: one permits Manager accounts to bypass collection management restrictions and perform administrative actions despite manage=false, and the other allows privilege escalation via the bulk-access API to gain access_all privileges. Both are network-exploitable with low complexity and no user interaction; administrators are urged to upgrade to Vaultwarden 1.35.4 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
