Access Control Flaw in Vaultwarden Affects Organization Members
CVE-2026-26012
Key Information:
- Vendor
Dani-garcia
- Status
- Vendor
- CVE Published:
- 11 February 2026
Badges
What is CVE-2026-26012?
Vaultwarden, an unofficial server compatible with Bitwarden, has a critical access control flaw that allows standard organization members to retrieve all ciphers from an organization, regardless of their collection permissions. Prior to version 1.35.3, the /ciphers/organization-details endpoint was accessible to any member of the organization, enabling them to access sensitive information without the necessary collection-level access control. This vulnerability poses a significant risk to data integrity and confidentiality within organizations using Vaultwarden.
Affected Version(s)
vaultwarden < 1.35.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
