Vault Unlocked: High-Severity Flaws in Vaultwarden Expose Encrypted Secrets and Allow Privilege Escalation
ID: 8b9626ec-11c7-5e2d-9422-fab538aeceed
STIX ID: report--8b9626ec-11c7-5e2d-9422-fab538aeceed
Feed Name: securityonline.info
Threat Score
**Executive summary:** Security researchers disclosed three critical CVEs in Vaultwarden 1.35.3: two flaws allow Manager-role permission bypass and bulk privilege escalation across collections, and a Partial Update endpoint leaks other users' encrypted vault entries and attachment download URLs; administrators should upgrade to Vaultwarden 1.35.4 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
