CVE-2026-27802

Description

A flaw was found in Vaultwarden. A manager, an authorized user, can exploit this vulnerability by performing a bulk permission update to collections they are not authorized to access. This can lead to privilege escalation, allowing the manager to gain unauthorized access and control over these collections.

Statement

IMPORTANT: This privilege escalation vulnerability in Vaultwarden allows a Manager to update permissions for unauthorized collections. This flaw affects Vaultwarden versions prior to 1.35.4, enabling a malicious or compromised Manager account to gain elevated privileges beyond their intended scope within the application.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Gain Privileges or Assume Identity

A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.

Frequently Asked Questions

Want to get errata notifications? Sign up here.