Management Authorization Flaw in Vaultwarden by Bitwarden
CVE-2026-27803
8.3HIGH
What is CVE-2026-27803?
Vaultwarden, an unofficial server compatible with Bitwarden, has a significant issue where a user with management rights set to false for a specific collection can still execute numerous management tasks if they have access to that collection. This flaw undermines the intended access controls and raises critical security risks related to data integrity and management permissions. The vulnerability has been addressed in Vaultwarden version 1.35.4, which users are strongly encouraged to upgrade to in order to mitigate potential exposure.
Affected Version(s)
vaultwarden < 1.35.4
