PT-2025-5347 · Unknown+1 · Vaultwarden+1

Elizarbatin

·

Published

2024-06-25

·

Updated

2025-08-20

·

CVE-2025-24365

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions vaultwarden versions prior to 1.33.0
Description The issue allows an attacker to obtain owner rights of another organization. To exploit this, the attacker must know the ID of the victim organization and be the owner or admin of another organization. This can be done by default, as anyone can create their own organization. The estimated number of potentially affected devices is not specified.
Recommendations For versions prior to 1.33.0, upgrade to version 1.33.0 to prevent unauthorized access. As a temporary workaround, consider restricting access to the organization management functionality until the issue is resolved. Additionally, it is recommended to disable any unused functionality in the application to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-5575
BDU:2025-05021
CVE-2025-24365
GHSA-J4H8-VCH3-F797

Affected Products

Alt Linux
Vaultwarden