Authorization Bypass in Vaultwarden Affects User Access Management
CVE-2026-33420
5.3MEDIUM
What is CVE-2026-33420?
In Vaultwarden, prior to version 1.35.5, a critical authorization bypass exists in the get_org_collections_details endpoint. This flaw allows Manager-role users without collections assigned to them to access sensitive organizational information, including collection names, UUIDs, and user-to-collection mappings. The missing authorization check poses significant risks of data leakage within an organization, making it imperative for users to upgrade to version 1.35.5 or later to ensure robust security against unauthorized data access.
Affected Version(s)
vaultwarden < 1.35.5
