CVE-2026-27802
Description
A flaw was found in Vaultwarden. A manager, an authorized user, can exploit this vulnerability by performing a bulk permission update to collections they are not authorized to access. This can lead to privilege escalation, allowing the manager to gain unauthorized access and control over these collections.
Statement
IMPORTANT: This privilege escalation vulnerability in Vaultwarden allows a Manager to update permissions for unauthorized collections. This flaw affects Vaultwarden versions prior to 1.35.4, enabling a malicious or compromised Manager account to gain elevated privileges beyond their intended scope within the application.
Understanding the Weakness (CWE)
Access Control
Technical Impact: Gain Privileges or Assume Identity
A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.