Логотип exploitDog
bind:CVE-2026-27898
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-27898

Количество 4

Количество 4

redhat логотип

CVE-2026-27898

23 дня назад

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial" Even though the standard retrieval API correctly denies access to that cipher, the partial update endpoint returns 200 OK and exposes cipherDetails (including name, notes, data, secureNote, etc.). This issue has been patched in version 1.35.4.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-27898

23 дня назад

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial" Even though the standard retrieval API correctly denies access to that cipher, the partial update endpoint returns 200 OK and exposes cipherDetails (including name, notes, data, secureNote, etc.). This issue has been patched in version 1.35.4.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2026-27898

23 дня назад

Vaultwarden is an unofficial Bitwarden compatible server written in Ru ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-w9f8-m526-h7fh

23 дня назад

Vaultwarden has Unauthorized Access via Partial Update API on Another User’s Cipher

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-27898

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial" Even though the standard retrieval API correctly denies access to that cipher, the partial update endpoint returns 200 OK and exposes cipherDetails (including name, notes, data, secureNote, etc.). This issue has been patched in version 1.35.4.

CVSS3: 6.5
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-27898

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial" Even though the standard retrieval API correctly denies access to that cipher, the partial update endpoint returns 200 OK and exposes cipherDetails (including name, notes, data, secureNote, etc.). This issue has been patched in version 1.35.4.

CVSS3: 5.4
0%
Низкий
23 дня назад
debian логотип
CVE-2026-27898

Vaultwarden is an unofficial Bitwarden compatible server written in Ru ...

CVSS3: 5.4
0%
Низкий
23 дня назад
github логотип
GHSA-w9f8-m526-h7fh

Vaultwarden has Unauthorized Access via Partial Update API on Another User’s Cipher

CVSS3: 5.4
0%
Низкий
23 дня назад

Уязвимостей на страницу