PT-2026-39862 · Unknown · Vaultwarden
Ch1Nhpd
·
Published
2026-05-11
·
Updated
2026-05-15
·
CVE-2026-43912
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Vaultwarden versions prior to 1.35.5
Description
Vaultwarden fails to verify that organization UUID entries in group and collection management are consistent. Specifically, the server does not enforce that a
groups users.users organizations uuid entry belongs to the same organization as groups.groups uuid, nor that a collections groups.collections uuid entry matches the organization of collections groups.groups uuid. This allows an attacker with administrative privileges in one organization and low-privileged access in another to bind a membership UUID from the second organization into a group in the first. By using an organization group with accessAll=true, the attacker can utilize the '/api/sync' and '/api/ciphers' endpoints to enumerate ciphers from the foreign organization. Once collection IDs are revealed, the attacker can bind those IDs to the group to obtain write access to the foreign organization's items.Recommendations
Update to version 1.35.5.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vaultwarden