Authorization Bypass in Vaultwarden Affects User Access Management
CVE-2026-33420

5.3MEDIUM

Key Information:

Vendor
CVE Published:
5 May 2026

What is CVE-2026-33420?

In Vaultwarden, prior to version 1.35.5, a critical authorization bypass exists in the get_org_collections_details endpoint. This flaw allows Manager-role users without collections assigned to them to access sensitive organizational information, including collection names, UUIDs, and user-to-collection mappings. The missing authorization check poses significant risks of data leakage within an organization, making it imperative for users to upgrade to version 1.35.5 or later to ensure robust security against unauthorized data access.

Affected Version(s)

vaultwarden < 1.35.5

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.