PT-2026-39861 · Unknown · Vaultwarden

·

CVE-2026-43911

·

Published

2026-05-11

·

Updated

2026-05-12

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Vaultwarden versions prior to 1.35.5
Description Refresh tokens are not invalidated when a user's security stamp is rotated during security-sensitive operations, such as password changes, KDF changes, key rotation, email changes, organization administrator password resets, or emergency access takeovers. This allows an attacker with a previously obtained refresh token to maintain session access even after the user has performed actions to secure their account.
Recommendations Update to version 1.35.5.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43911
GHSA-6J4W-G4JH-XJFX

Affected Products

Vaultwarden