Junglewise Threat Intelligence

CVE-2026-27801: Vaultwarden has 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement

CVE-2026-27801 · Severity: medium · CVSS 4 · Published 2026-03-04

Technologies: vaultwarden (crates.io). Vendors: crates.io.

Executive brief

Vaultwarden has 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement

Affected products

  • crates.io vaultwarden

Related threats