Dani-garcia
Dani-garcia Vaultwarden: vulnerabilidades y CVE
Dani-garcia Vaultwarden tiene 25 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses16
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-95814 | Alta (8.6) | 0.43% | — | 22 sept 2026 | Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment… |
| CVE-2026-47164 | Alta (7.7) | 0.45% | — | 15 jul 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true… |
| CVE-2026-47160 | Media (5.8) | 0.40% | — | 15 jul 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_block_address() and post_resolve() that… |
| CVE-2026-47159 | Media (6.9) | 0.66% | — | 15 jul 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for… |
| CVE-2026-47158 | Alta (8.3) | 0.25% | — | 15 jul 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser… |
| CVE-2026-43914 | Crítica (9.8) | 0.49% | — | 11 may 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is enabled. If email… |
| CVE-2026-43913 | Alta (8.1) | 0.40% | — | 11 may 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The organization invite flow uses a two-step… |
| CVE-2026-43912 | Alta (8.7) | 0.40% | — | 11 may 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as groups.groups_uuid, or a… |
| CVE-2026-43911 | Alta (8.1) | 0.31% | — | 11 may 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (password change, KDF… |
| CVE-2026-33420 | Media (5.3) | 0.28% | — | 5 may 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing the… |
| CVE-2026-31835 | Media (5.3) | 0.19% | — | 5 may 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authentication flow in `validate_webauthn_login()` updates persistent credential metadata (1backup_eligible1 and… |
| CVE-2026-27898 | Media (5.4) | 0.24% | — | 4 mar 2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT… |
| CVE-2026-27803 | Alta (8.3) | 0.39% | — | 4 mar 2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several… |
| CVE-2026-27802 | Alta (8.3) | 0.39% | — | 4 mar 2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized… |
| CVE-2026-27801 | Media (6) | 0.25% | — | 4 mar 2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An… |
| CVE-2026-26012 | Media (6.5) | 0.38% | — | 11 feb 2026 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35.3, a regular organization member can retrieve all ciphers within an organization, regardless of… |
| CVE-2025-24365 | Alta (7.5) | 0.68% | — | 27 ene 2025 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real… |
| CVE-2025-24364 | Alta (7.2) | 1.0% | — | 27 ene 2025 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker with authenticated access to the vaultwarden admin panel can execute arbitrary code in the system. The… |
| CVE-2024-55226 | Media (5.4) | 0.38% | — | 9 ene 2025 | Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs. |
| CVE-2024-55225 | Crítica (9.8) | 0.60% | — | 9 ene 2025 | An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request. |
| CVE-2024-55224 | Crítica (9.6) | 0.82% | — | 9 ene 2025 | An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message. |
| CVE-2024-56335 | Alta (7.5) | 0.34% | — | 20 dic 2024 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few… |
| CVE-2024-39926 | Media (5.4) | 0.46% | — | 13 sept 2024 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This… |
| CVE-2024-39925 | Media (6.5) | 0.57% | — | 13 sept 2024 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member… |
| CVE-2024-39924 | Alta (8.8) | 13% | — | 13 sept 2024 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.