Executive brief
Vaultwarden is an open-source password management server. A security flaw allows users with a 'Manager' role to view information about all password collections within an organization, even if they haven't been granted permission to see them. This could allow an internal user to see sensitive collection names and identify which employees have access to specific sets of credentials.
Technical details
The 'get_org_collections_details' endpoint (GET /api/organizations/{org_id}/collections/details) in 'src/api/core/organizations.rs' fails to implement the 'has_full_access()' authorization check. While the sibling 'get_org_collections' endpoint correctly restricts access, this specific endpoint only requires 'ManagerHeadersLoose' and returns all collections via 'Collection::find_by_organization()'. An authenticated attacker with a Manager role can exploit this to retrieve collection names, UUIDs, and user/group-to-collection mappings for the entire organization, regardless of their specific assignments. This issue is fixed in version 1.35.5.
Affected products
- dani-garcia Vaultwarden <= 1.35.4
Timeline
- 2026-04-26: advisory: GitHub Security Advisory published
- 2026-05-05: disclosed: CVE published to NVD
- 2026-04-12: patched: Version 1.35.5 released