Vendorsdani-garciavaultwardenall versions
Vulnerabilities

dani-garcia (Daniel Garcia) Vaultwarden

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2024-55225
An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.
Published 2025-01-09 · Analyzed
9.8EPSS 0.006
CVE-2026-43914
Vaultwarden: Brute-force protection bypass vulnerability
Published 2026-05-11 · Analyzed
9.8EPSS 0.005
CVE-2024-55224
An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.
Published 2025-01-09 · Analyzed
9.6EPSS 0.008
CVE-2024-39924
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an attacker with granted emergency access to escalate their privileges by changing the access level and modifying the wait time. Consequently, the attacker can gain full control over the vault (when only intended to have read access) while bypassing the necessary wait period.
Published 2024-09-13 · Analyzed
8.8EPSS 0.133
CVE-2026-43912
Vaultwarden: Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Another Organization
Published 2026-05-11 · Analyzed
8.7EPSS 0.004
CVE-2026-27802
Vaultwarden: Privilege Escalation via Bulk Permission Update to Unauthorized Collections by Manager
Published 2026-03-04 · Analyzed
8.3EPSS 0.004
CVE-2026-27803
Vaultwarden: Collection Management Operations Allowed Without `manage` Verification for Manager Role
Published 2026-03-04 · Analyzed
8.3EPSS 0.004
CVE-2025-24365
vaultwarden allows escalation of privilege via variable confusion in OrgHeaders trait
Published 2025-01-27 · Analyzed
8.1EPSS 0.007
CVE-2026-43913
Vaultwarden: Unconfirmed Owner Can Purge Entire Organization Vault
Published 2026-05-11 · Analyzed
8.1EPSS 0.004
CVE-2026-43911
Vaultwarden: Refresh tokens not invalidated on security stamp rotation
Published 2026-05-11 · Analyzed
8.1EPSS 0.003
CVE-2024-56335
Privilege escalation allows organization groups to be updated/deleted if their UUID is known in vaultwarden
Published 2024-12-20 · Analyzed
7.6EPSS 0.003
CVE-2025-24364
vaultwarden allows RCE in the admin panel
Published 2025-01-27 · Analyzed
7.2EPSS 0.010
CVE-2024-39925
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member departs. Consequently, the departing member, whose access should be revoked, retains a copy of the organization key. Additionally, the application fails to adequately protect some encrypted data stored on the server. Consequently, an authenticated user could gain unauthorized access to encrypted data of any organization, even if the user is not a member of the targeted organization. However, the user would need to know the corresponding organizationId. Hence, if a user (whose access to an organization has been revoked) already possesses the organization key, that user could use the key to decrypt the leaked data.
Published 2024-09-13 · Analyzed
6.5EPSS 0.006
CVE-2026-26012
vaultwarden has Full Cipher Enumeration Ignoring Organization Collection Permissions
Published 2026-02-11 · Analyzed
6.5EPSS 0.004
CVE-2026-27801
Vaultwarden: 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement
Published 2026-03-04 · Analyzed
6.0EPSS 0.002
CVE-2024-39926
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This potentially allows an authenticated attacker to inject malicious code into the dashboard, which is then executed or rendered in the context of an administrator's browser when viewing the injected content. However, it is important to note that the default Content Security Policy (CSP) of the application blocks most exploitation paths, significantly mitigating the potential impact.
Published 2024-09-13 · Analyzed
5.4EPSS 0.005
CVE-2024-55226
Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.
Published 2025-01-09 · Analyzed
5.4EPSS 0.004
CVE-2026-27898
Vaultwarden: Unauthorized Access via Partial Update API on Another User’s Cipher
Published 2026-03-04 · Analyzed
5.4EPSS 0.002
CVE-2026-31835
Vaultwarden WebAuthn credential metadata tampered before signature verification
Published 2026-05-05 · Analyzed
5.4EPSS 0.002
CVE-2026-33420
Vaultwarden missing authorization check allows Manager-role users to enumerate all collections
Published 2026-05-05 · Analyzed
5.3EPSS 0.003