CVE-2026-27802Disclosure(dani-garcia / vaultwarden)

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dani-garcia vaultwarden systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized collections by Manager. This issue has been patched in version 1.35.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vaultwarden

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-04); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
vaultwarden

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Mentions · 2026-03-16: 1Patch / Workaround · 2026-03-04: 2Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-04: 2Technical Details · 2026-03-05: 1Technical Details · 2026-03-16: 103-0403-0503-16
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure2
2026-03-051
Patch1
2026-03-161
Patch1
Full discourse4 posts
  • iototsecnews@iototsecnews
    Patch

    Vaultwarden の脆弱性 CVE-2026-27802/27803 が FIX:権限昇格とデータ漏洩の可能性 https://iototsecnews.jp/2026/03/09/vaultwarden-vulnerabilities-enable-privilege-escalation-and-data-exposure/ 今回の脆弱性の原因は、本来行われるべき認可チェックが、特定の条件下で機能していなかったことにあります。脆弱性 CVE-2026-27803 では、設定により制限されるはずの管理コマンドが、不適切な権限管理により実行されてしまうという状態でした。また、 CVE-2026-27802 では、一括処理を行う API (bulk-access API ) において、個別の更新時には適用される認証チェックが漏れてしまうという問題が発生しています。ご利用のチームに推奨されるのは、修正済みバージョンへの速やかな更新です。 #CVE202627802 #CVE202627803 #Vaultwarden #Vulnerability

    Post summary

    The article reports two new Vaultwarden vulnerabilities (CVE‑2026‑27802 and CVE‑2026‑27803) that allow privilege escalation and data leakage due to missing authorization checks, and urges users to update to the patched version immediately.

    01000123
    484 followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    🟠 CVE-2026-27802 - High Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permi... https://www.thehackerwire.com/vulnerability/CVE-2026-27802/ https://t.co/kELjVAOOJ4

    Post summary

    The post highlights a privilege‑escalation flaw in Vaultwarden version 1.35.3 and earlier, stating that the issue is addressed by upgrading to version 1.35.4.

    1000065
    124 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27802 Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vul… https://www.cve.org/CVERecord?id=CVE-2026-27802 ----- Traducción: CVE-2026-27802 Vau… http://infoflow.cloud`

    Post summary

    CVE‑2026‑27802 involves a privilege‑escalation flaw in Vaultwarden that existed before v1.35.4, which has been addressed in that release. No PoC, exploit, or active exploitation details are disclosed.

    0001048
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27802 Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vul… https://www.cve.org/CVERecord?id=CVE-2026-27802

    Post summary

    The text discloses a privilege escalation CVE affecting Vaultwarden before version 1.35.4 and implies a patch is available, but does not indicate any PoC, exploit, or active exploitation.

    00010226
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdani-garciavaultwarden---

Explore more