{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3avaultwardenvaultwarden/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vaultwarden:vaultwarden:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-95814"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Vaultwarden (\u003c= 1.37.3)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","access-control","authentication"],"_cs_type":"advisory","_cs_vendors":["Vaultwarden"],"content_html":"\u003cp\u003eVaultwarden versions 1.37.3 and earlier contain a critical vulnerability in the organization access control logic. The application fails to properly enforce membership status checks within key cipher access-restriction functions, specifically \u003ccode\u003eget_user_collections_access_flags\u003c/code\u003e, \u003ccode\u003eget_group_collections_access_flags\u003c/code\u003e, and \u003ccode\u003eis_in_full_access_group\u003c/code\u003e. As a result, users who have been revoked from an organization or users whose membership is currently in a pending state retain their ability to perform read, write, and delete operations on organization-managed ciphers, as well as interact with associated attachments. This flaw allows unauthorized individuals to access or modify protected credentials beyond their intended privilege level. Defenders should prioritize updating to the latest patched version to ensure proper access control enforcement.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized users to access, modify, or delete organization-wide secrets and attachments. This could lead to massive credential exposure within enterprise Vaultwarden deployments, effectively granting revoked or unvetted users complete control over corporate secrets.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Vaultwarden instances to a version later than 1.37.3 immediately.\u003c/li\u003e\n\u003cli\u003eReview organization audit logs for access activity by users with revoked or pending statuses.\u003c/li\u003e\n\u003cli\u003eEnsure all service accounts and API clients utilizing the Vaultwarden API are patched and audited for abnormal cipher access patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T00:39:54Z","date_published":"2026-09-23T00:39:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-vaultwarden-auth-bypass/","summary":"Vaultwarden versions 1.37.3 and earlier fail to validate organization membership status, allowing revoked or pending members to retain unauthorized access to sensitive cipher data.","title":"Vaultwarden Access Control Bypass via Membership Validation Failure","url":"https://feed.craftedsignal.io/briefs/2026-09-vaultwarden-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:vaultwarden:vaultwarden:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}