CVE-2026-27803Patch(dani-garcia / vaultwarden)

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dani-garcia vaultwarden systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations as long as they have access to the collection. This issue has been patched in version 1.35.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-285CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vaultwarden

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-04); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
vaultwarden

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Mentions · 2026-03-16: 1Mentions · 2026-06-12: 1Patch / Workaround · 2026-03-04: 2Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-06-12: 1Technical Details · 2026-03-16: 1Technical Details · 2026-06-12: 103-0403-0503-1606-12
Signal classification2 categories
Patch
480.0%
Disclosure
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure1Patch1
2026-03-051
Patch1
2026-03-161
Patch1
2026-06-121
Patch1
Full discourse5 posts
  • iototsecnews@iototsecnews
    Patch

    Vaultwarden の脆弱性 CVE-2026-27802/27803 が FIX:権限昇格とデータ漏洩の可能性 https://iototsecnews.jp/2026/03/09/vaultwarden-vulnerabilities-enable-privilege-escalation-and-data-exposure/ 今回の脆弱性の原因は、本来行われるべき認可チェックが、特定の条件下で機能していなかったことにあります。脆弱性 CVE-2026-27803 では、設定により制限されるはずの管理コマンドが、不適切な権限管理により実行されてしまうという状態でした。また、 CVE-2026-27802 では、一括処理を行う API (bulk-access API ) において、個別の更新時には適用される認証チェックが漏れてしまうという問題が発生しています。ご利用のチームに推奨されるのは、修正済みバージョンへの速やかな更新です。 #CVE202627802 #CVE202627803 #Vaultwarden #Vulnerability

    Post summary

    The article reports on CVE‑2026‑27802 and CVE‑2026‑27803 in Vaultwarden, detailing privilege‑escalation and data‑exposure vulnerabilities, and urges teams to upgrade immediately to the patched release.

    01000123
    484 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27803 Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for… https://www.cve.org/CVERecord?id=CVE-2026-27803 ----- Traducción: CVE-2026-27803 Vau… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-27803 for Vaultwarden, noting the issue existed prior to version 1.35.4, and links to the CVE record, but provides no further exploitation details.

    0001045
    55 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-27803 Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for… https://www.cve.org/CVERecord?id=CVE-2026-27803

    Post summary

    The vulnerability CVE-2026-27803 affects Vaultwarden before version 1.35.4 when a Manager has manage=false, but the issue is resolved in that release.

    00010218
    56.6K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Fedora released Vaultwarden fixes for Fedora 43 and 44 to address CVE-2026-27801 two-factor authentication bypass and CVE-2026-27803 unauthorized collection management flaws, Linuxsecurity reported. https://threatcluster.io/cluster/critical-security-flaws-in-vaultwarden-affecting-fedora-43-a-e75ff84b

    Post summary

    Fedora issued updates for Vaultwarden to fix two-factor authentication bypass and unauthorized collection management issues associated with CVE-2026-27801 and CVE-2026-27803.

    0000057
    330 followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    🟠 CVE-2026-27803 - High Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they... https://www.thehackerwire.com/vulnerability/CVE-2026-27803/ https://t.co/7U4L4Ulr4t

    Post summary

    The tweet announces CVE-2026‑27803 and notes that Vaultwarden versions before 1.35.4 are vulnerable, implying a patch is available in that version, but no exploit details are provided.

    0000059
    124 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdani-garciavaultwarden---

Explore more