« Volver al listado

Dani-garcia

Dani-garcia Vaultwarden: vulnerabilidades y CVE

Dani-garcia Vaultwarden tiene 25 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE25
Últimos 12 meses16
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-95814Alta (8.6)0.43%—22 sept 2026
Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment…
CVE-2026-47164Alta (7.7)0.45%—15 jul 2026
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true…
CVE-2026-47160Media (5.8)0.40%—15 jul 2026
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_block_address() and post_resolve() that…
CVE-2026-47159Media (6.9)0.66%—15 jul 2026
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for…
CVE-2026-47158Alta (8.3)0.25%—15 jul 2026
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser…
CVE-2026-43914Crítica (9.8)0.49%—11 may 2026
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is enabled. If email…
CVE-2026-43913Alta (8.1)0.40%—11 may 2026
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The organization invite flow uses a two-step…
CVE-2026-43912Alta (8.7)0.40%—11 may 2026
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as groups.groups_uuid, or a…
CVE-2026-43911Alta (8.1)0.31%—11 may 2026
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (password change, KDF…
CVE-2026-33420Media (5.3)0.28%—5 may 2026
Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing the…
CVE-2026-31835Media (5.3)0.19%—5 may 2026
Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authentication flow in `validate_webauthn_login()` updates persistent credential metadata (1backup_eligible1 and…
CVE-2026-27898Media (5.4)0.24%—4 mar 2026
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT…
CVE-2026-27803Alta (8.3)0.39%—4 mar 2026
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several…
CVE-2026-27802Alta (8.3)0.39%—4 mar 2026
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized…
CVE-2026-27801Media (6)0.25%—4 mar 2026
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An…
CVE-2026-26012Media (6.5)0.38%—11 feb 2026
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35.3, a regular organization member can retrieve all ciphers within an organization, regardless of…
CVE-2025-24365Alta (7.5)0.68%—27 ene 2025
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real…
CVE-2025-24364Alta (7.2)1.0%—27 ene 2025
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker with authenticated access to the vaultwarden admin panel can execute arbitrary code in the system. The…
CVE-2024-55226Media (5.4)0.38%—9 ene 2025
Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.
CVE-2024-55225Crítica (9.8)0.60%—9 ene 2025
An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.
CVE-2024-55224Crítica (9.6)0.82%—9 ene 2025
An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.
CVE-2024-56335Alta (7.5)0.34%—20 dic 2024
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few…
CVE-2024-39926Media (5.4)0.46%—13 sept 2024
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This…
CVE-2024-39925Media (6.5)0.57%—13 sept 2024
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member…
CVE-2024-39924Alta (8.8)13%—13 sept 2024
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services9
  2. T1078 Valid Accounts4
  3. T1190 Exploit Public-Facing Application3
  4. T1068 Exploitation for Privilege Escalation2
  5. T1059 Command and Scripting Interpreter1
  6. T1059.007 JavaScript1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.