PT-2024-36796 · Unknown+1 · Vaultwarden+1

Blackdex

+1

·

Published

2024-12-20

·

Updated

2025-08-19

·

CVE-2024-56335

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions vaultwarden versions prior to 1.32.7
Description The issue allows an attacker to update or delete groups from an organization under certain conditions: the attacker has a user account in the server, the attacker's account has admin or owner permissions in an unrelated organization, and the attacker knows the target organization's UUID and the target group's UUID. This can lead to denial of service or privilege escalation. The attack is only applicable for servers with the ORG GROUPS ENABLED setting enabled, which is disabled by default.
Recommendations For versions prior to 1.32.7, update to version 1.32.7 as soon as possible. If updating to 1.32.7 is not possible, consider disabling the ORG GROUPS ENABLED setting to disable groups functionality on the server. Alternatively, disabling SIGNUPS ALLOWED can prevent an attacker from creating new accounts on the server.

Exploit

Fix

DoS

LPE

Improper Access Control

Improper Authentication

Improper Authorization

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ALT-PU-2025-5575
CVE-2024-56335
GHSA-G65H-982X-4M5M

Affected Products

Alt Linux
Vaultwarden