logo

Vault Unlocked: High-Severity Flaws in Vaultwarden Expose Encrypted Secrets and Allow Privilege Escalation

ID: 8b9626ec-11c7-5e2d-9422-fab538aeceed

STIX ID: report--8b9626ec-11c7-5e2d-9422-fab538aeceed

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-09

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive summary:** Security researchers disclosed three critical CVEs in Vaultwarden 1.35.3: two flaws allow Manager-role permission bypass and bulk privilege escalation across collections, and a Partial Update endpoint leaks other users' encrypted vault entries and attachment download URLs; administrators should upgrade to Vaultwarden 1.35.4 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.