Authorization Bypass in Vaultwarden by Dani Garcia
CVE-2026-95814

8.6HIGH

Key Information:

Vendor
CVE Published:
22 September 2026

What is CVE-2026-95814?

Vaultwarden versions up to 1.37.3 are vulnerable due to a failure to validate organization membership status during key access-restriction queries. This oversight allows users with revoked or pending memberships to exploit the system, maintaining read, write, delete, and attachment access to sensitive cipher data. Attackers can leverage this vulnerability by bypassing required status filters, leading to unauthorized access to protected information on the server side.

Affected Version(s)

vaultwarden 0 <= 1.37.3

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Siyang Wu
.