Management Authorization Flaw in Vaultwarden by Bitwarden
CVE-2026-27803

8.3HIGH

Key Information:

Vendor
CVE Published:
4 March 2026

What is CVE-2026-27803?

Vaultwarden, an unofficial server compatible with Bitwarden, has a significant issue where a user with management rights set to false for a specific collection can still execute numerous management tasks if they have access to that collection. This flaw undermines the intended access controls and raises critical security risks related to data integrity and management permissions. The vulnerability has been addressed in Vaultwarden version 1.35.4, which users are strongly encouraged to upgrade to in order to mitigate potential exposure.

Affected Version(s)

vaultwarden < 1.35.4

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.