PT-2026-37215 · Unknown · Vaultwarden

Dorakemon

·

Published

2026-05-05

·

Updated

2026-05-05

·

CVE-2026-31835

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vaultwarden versions prior to 1.35.5
Description The WebAuthn authentication flow in the validate webauthn login() function updates persistent credential metadata, specifically the backup eligible and backup state flags, using unverified authenticatorData before signature validation occurs. An attacker possessing a user's password can permanently modify these stored backup flags even without a valid WebAuthn signature, as database updates are not rolled back upon signature verification failure. This leads to a persistent denial of service for WebAuthn two-factor authentication for the affected credentials.
Recommendations Update to version 1.35.5.

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2026-31835

Affected Products

Vaultwarden