PT-2026-39863 · Unknown · Vaultwarden
Ch1Nhpd
·
Published
2026-05-11
·
Updated
2026-05-12
·
CVE-2026-43913
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vaultwarden versions prior to 1.35.5
Description
Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The issue exists because the 'POST /api/ciphers/purge' endpoint verifies that a user has the
Owner membership type but fails to verify that the membership status is Confirmed. Consequently, an authenticated user who has accepted an organization owner invite but has not yet been confirmed by an existing owner can call this endpoint to permanently delete all ciphers and attachments within the organization, leading to immediate data loss.Recommendations
Update to version 1.35.5.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vaultwarden