CVE-2026-27803
Description
A flaw was found in Vaultwarden. An authenticated manager, even when explicitly denied management privileges for a collection, could still perform various unauthorized management operations on that collection. This improper access control could lead to unauthorized information disclosure and data modification within the affected collection.
Statement
This is an IMPORTANT flaw in Vaultwarden, an unofficial Bitwarden compatible server. A manager with manage=false for a collection can still perform management operations on collections they have access to. Red Hat only ships Vaultwarden in community products - EPEL and Fedora
Understanding the Weakness (CWE)
Access Control
Technical Impact: Gain Privileges or Assume Identity
A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.