PT-2026-39861 · Unknown · Vaultwarden
Qaz741Wsd856
·
Published
2026-05-11
·
Updated
2026-05-12
·
CVE-2026-43911
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Vaultwarden versions prior to 1.35.5
Description
Refresh tokens are not invalidated when a user's
security stamp is rotated during security-sensitive operations, such as password changes, KDF changes, key rotation, email changes, organization administrator password resets, or emergency access takeovers. This allows an attacker with a previously obtained refresh token to maintain session access even after the user has performed actions to secure their account.Recommendations
Update to version 1.35.5.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vaultwarden