Junglewise Threat Intelligence

CVE-2026-95814: Vaultwarden authorization bypass in cipher access queries

CVE-2026-95814 · Severity: high · CVSS 8.1 · Published 2026-09-22

Technologies: Dani-Garcia Vaultwarden. Vendors: Dani-Garcia.

Executive brief

Vaultwarden is a password manager server compatible with Bitwarden. An authorization flaw allows users whose organization membership has been revoked or is pending approval to retain access to sensitive password vaults and encrypted data. An attacker could exploit this to access, modify, or delete secrets belonging to the organization even after their membership should have been terminated.

Technical details

Three cipher access-restriction queries (get_user_collections_access_flags, get_group_collections_access_flags, is_in_full_access_group) fail to validate organization membership status, permitting revoked and pending members to bypass access controls. The vulnerability is exploitable server-side without user interaction; attackers with former or pending organization membership can read, write, delete, and access attachments on protected organization ciphers.

Affected products

  • dani-garcia Vaultwarden through 1.37.3

Timeline

  • 2026-09-22: disclosed

References

Related threats