← Back to CVE List
CVE-2026-27803NVD
Vulnerability Summary
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations as long as they have access to the collection. This issue has been patched in version 1.35.4.
CVSS v3.1 Base Metrics — Score 8.3 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityLow
Affected & Patched Versions
- Dani-garcia Vaultwarden < 1.35.4
- Dani-garcia Vaultwarden 1.35.4