Executive brief
Vaultwarden has 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement
Affected products
- crates.io vaultwarden
Junglewise Threat Intelligence
CVE-2026-27801 · Severity: medium · CVSS 4 · Published 2026-03-04
Technologies: vaultwarden (crates.io). Vendors: crates.io.
Vaultwarden has 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement