CVE-2026-27801Disclosure(dani-garcia / vaultwarden)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dani-garcia vaultwarden systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authenticated access to a user’s account can exploit this bypass to perform protected actions such as accessing the user’s API key or deleting the user’s vault and organisations the user is an admin/owner of . This issue has been patched in version 1.35.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vaultwarden

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-04); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
vaultwarden

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-04: 3Mentions · 2026-06-12: 1Patch / Workaround · 2026-06-12: 1Technical Details · 2026-03-04: 1Technical Details · 2026-06-12: 103-0406-12
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-043
Disclosure2General1
2026-06-121
Patch1
Full discourse4 posts
  • ThreatCluster@threatcluster
    Patch

    Fedora released Vaultwarden fixes for Fedora 43 and 44 to address CVE-2026-27801 two-factor authentication bypass and CVE-2026-27803 unauthorized collection management flaws, Linuxsecurity reported. https://threatcluster.io/cluster/critical-security-flaws-in-vaultwarden-affecting-fedora-43-a-e75ff84b

    Post summary

    Fedora has issued patches for Vaultwarden to mitigate CVE-2026-27801 (two-factor authentication bypass) and CVE-2026-27803 (unauthorized collection management), with no mention of active exploitation or PoC.

    0000057
    330 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27801 Two-Factor Authentication Bypass in Vaultwarden Versions 1.34.3 and Prior https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27801

    Post summary

    A new authentication bypass vulnerability (CVE‑2026‑27801) affecting Vaultwarden 1.34.3 and earlier has been publicly disclosed, but there is no evidence of a PoC, exploit, or active exploitation, nor is a patch mentioned.

    0000054
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27801 Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2… https://www.cve.org/CVERecord?id=CVE-2026-27801 ----- Traducción: CVE-2026-27801 Vau… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑27801 affecting Vaultwarden versions 1.34.3 and earlier, but it offers no further technical details, PoC, exploit code, or mitigation information.

    0000042
    55 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27801 Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2… https://www.cve.org/CVERecord?id=CVE-2026-27801

    Post summary

    The text references CVE-2026-27801 affecting Vaultwarden <1.34.3 but provides minimal technical detail and no evidence of PoC, exploitation, or patch availability.

    00000253
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdani-garciavaultwarden---

Explore more