Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27898

Опубликовано: 04 мар. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial" Even though the standard retrieval API correctly denies access to that cipher, the partial update endpoint returns 200 OK and exposes cipherDetails (including name, notes, data, secureNote, etc.). This issue has been patched in version 1.35.4.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dani-garcia:vaultwarden:*:*:*:*:*:*:*:*
Версия до 1.35.4 (исключая)

EPSS

Процентиль: 9%
0.0003
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
redhat
23 дня назад

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial" Even though the standard retrieval API correctly denies access to that cipher, the partial update endpoint returns 200 OK and exposes cipherDetails (including name, notes, data, secureNote, etc.). This issue has been patched in version 1.35.4.

CVSS3: 5.4
debian
23 дня назад

Vaultwarden is an unofficial Bitwarden compatible server written in Ru ...

CVSS3: 5.4
github
23 дня назад

Vaultwarden has Unauthorized Access via Partial Update API on Another User’s Cipher

EPSS

Процентиль: 9%
0.0003
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-639