Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27801

Опубликовано: 04 мар. 2026
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authenticated access to a user’s account can exploit this bypass to perform protected actions such as accessing the user’s API key or deleting the user’s vault and organisations the user is an admin/owner of . This issue has been patched in version 1.35.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dani-garcia:vaultwarden:*:*:*:*:*:*:*:*
Версия до 1.35.0 (исключая)

EPSS

Процентиль: 9%
0.00031
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 8.8
redhat
23 дня назад

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authenticated access to a user’s account can exploit this bypass to perform protected actions such as accessing the user’s API key or deleting the user’s vault and organisations the user is an admin/owner of . This issue has been patched in version 1.35.0.

CVSS3: 5.9
debian
23 дня назад

Vaultwarden is an unofficial Bitwarden compatible server written in Ru ...

github
23 дня назад

Vaultwarden has 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement

EPSS

Процентиль: 9%
0.00031
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-307