CVE-2026-33420Disclosure(dani-garcia / vaultwarden)

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing the has_full_access() authorization check that exists on the sibling get_org_collections endpoint. This allows any Manager-role user with accessAll=False and no collection assignments to retrieve the names, UUIDs, user-to-collection mappings, and group-to-collection mappings for all collections in the organization. This issue has been fixed in version 1.35.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vaultwarden

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Products
vaultwarden

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-05: 3Technical Details · 2026-05-05: 205-05
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33420 Authorization Bypass in Vaultwarden 1.35.4 and Earlier Versions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33420 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE‑2026‑33420 as an authorization bypass in Vaultwarden up to version 1.35.4, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0000039
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33420 Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}… https://www.cve.org/CVERecord?id=CVE-2026-33420 ----- Traducción: CVE-2026-33420 Vau… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑33420 affecting Vaultwarden versions up to 1.35.4, detailing the vulnerable GET endpoint and linking to the CVE record.

    0000039
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33420 Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}… https://www.cve.org/CVERecord?id=CVE-2026-33420

    Post summary

    The snippet references CVE-2026-33420 and notes the affected endpoint in Vaultwarden, but it does not provide further details about exploitation, patches, or technical specifics.

    00000156
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdani-garciavaultwarden---

Explore more