Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-27802

Опубликовано: 04 мар. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized collections by Manager. This issue has been patched in version 1.35.4.

A flaw was found in Vaultwarden. A manager, an authorized user, can exploit this vulnerability by performing a bulk permission update to collections they are not authorized to access. This can lead to privilege escalation, allowing the manager to gain unauthorized access and control over these collections.

Отчет

IMPORTANT: This privilege escalation vulnerability in Vaultwarden allows a Manager to update permissions for unauthorized collections. This flaw affects Vaultwarden versions prior to 1.35.4, enabling a malicious or compromised Manager account to gain elevated privileges beyond their intended scope within the application.

Дополнительная информация

Статус:

Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2444676vaultwarden: Vaultwarden: Privilege Escalation via Unauthorized Bulk Permission Update

EPSS

Процентиль: 14%
0.00045
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
nvd
23 дня назад

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized collections by Manager. This issue has been patched in version 1.35.4.

CVSS3: 8.3
debian
23 дня назад

Vaultwarden is an unofficial Bitwarden compatible server written in Ru ...

CVSS3: 8.3
github
23 дня назад

Vaultwarden has Privilege Escalation via Bulk Permission Update to Unauthorized Collections by Manager

EPSS

Процентиль: 14%
0.00045
Низкий

8.1 High

CVSS3