CVE-2026-27803

Description

A flaw was found in Vaultwarden. An authenticated manager, even when explicitly denied management privileges for a collection, could still perform various unauthorized management operations on that collection. This improper access control could lead to unauthorized information disclosure and data modification within the affected collection.

Statement

This is an IMPORTANT flaw in Vaultwarden, an unofficial Bitwarden compatible server. A manager with manage=false for a collection can still perform management operations on collections they have access to. Red Hat only ships Vaultwarden in community products - EPEL and Fedora

Understanding the Weakness (CWE)

Access Control

Technical Impact: Gain Privileges or Assume Identity

A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.

Frequently Asked Questions

Want to get errata notifications? Sign up here.