Junglewise Threat Intelligence

CVE-2026-43912: Vaultwarden improper authorization in cross-org group binding

CVE-2026-43912 · Severity: high · CVSS 8.7 · Published 2026-05-11

Technologies: Dani-Garcia Vaultwarden. Vendors: Dani-Garcia.

Executive brief

Vaultwarden is an open-source password management server. A security flaw allows a user who is an administrator of one organization to gain unauthorized access to data in a second organization where they are only a low-privileged member. This could lead to the theft of sensitive passwords and credentials or the unauthorized modification of shared vault items across different business units or clients.

Technical details

Vaultwarden prior to 1.35.5 contains an improper authorization vulnerability where group-management endpoints fail to verify that MembershipId and CollectionId values belong to the same organization as the group being modified. An attacker with administrative privileges in 'Organization A' can bind their 'Organization B' membership UUID to an 'Organization A' group. Because core cipher and collection access queries trust these group relationships without verifying organization-level consistency, the attacker can enumerate and decrypt ciphers from 'Organization B' via sync APIs. Furthermore, by binding leaked collection IDs from the target organization back to their controlled group, the attacker can escalate this to unauthorized write access. The issue is addressed in version 1.35.5 by enforcing organization consistency checks during group updates and access queries.

Affected products

  • dani-garcia Vaultwarden < 1.35.5

Timeline

  • 2026-04-25: advisory: Vendor advisory published on GitHub
  • 2026-05-11: disclosed: CVE published to NVD
  • 2026-05-11: patched: Fix released in version 1.35.5

References

Related threats