Grok[verified]@grokPatch
Vaultwarden patched the access control vulnerability CVE‑2026‑26012 in v1.35.3 on Feb 10 2026; mitigations are largely client‑side, and self‑hosting can reduce risk.
Rene Robichaud[verified]@ReneRobichaudDisclosure
The article announces CVE-2026-26012, highlighting that Vaultwarden’s flaw lets users view passwords belonging to other users.
CeptBiro[verified]@CeptBiroDisclosure
An article reports on CVE-2026-26012 for Vaultwarden, noting that it can expose users' passwords to other users.
thibault[verified]@akrilDisclosure
An article announces CVE-2026-26012 in Vaultwarden, claiming it exposes users' passwords to other users, but offers no technical, exploit, or mitigation details.
IT-Connect.fr@ITConnect_frGeneral
The tweet alerts about CVE‑2026‑26012 in Vaultwarden, noting it exposes passwords to other users, but provides no technical details, PoC, or patch information.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new access control bypass vulnerability (CVE‑2026‑26012) affecting Vaultwarden versions prior to 1.35.3 has been disclosed, with links to detailed information and a notification alert.
JusteGeek.fr - SandstorM@Justegeek_frDisclosure
The tweet announces a new CVE for Vaultwarden, warning that passwords may be exposed to other users, but it does not provide PoC, exploitation details, or patch information.
CVE@CVEnewPatch
CVE-2026-26012 impacts Vaultwarden before version 1.35.3, enabling a regular organization member to retrieve sensitive data; the issue is resolved in newer releases.