<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:vaultwarden:vaultwarden:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3avaultwardenvaultwarden/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 23 Sep 2026 00:39:54 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3avaultwardenvaultwarden/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Vaultwarden Access Control Bypass via Membership Validation Failure</title><link>https://feed.craftedsignal.io/briefs/2026-09-vaultwarden-auth-bypass/</link><pubDate>Wed, 23 Sep 2026 00:39:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-vaultwarden-auth-bypass/</guid><description>Vaultwarden versions 1.37.3 and earlier fail to validate organization membership status, allowing revoked or pending members to retain unauthorized access to sensitive cipher data.</description><content:encoded><![CDATA[<p>Vaultwarden versions 1.37.3 and earlier contain a critical vulnerability in the organization access control logic. The application fails to properly enforce membership status checks within key cipher access-restriction functions, specifically <code>get_user_collections_access_flags</code>, <code>get_group_collections_access_flags</code>, and <code>is_in_full_access_group</code>. As a result, users who have been revoked from an organization or users whose membership is currently in a pending state retain their ability to perform read, write, and delete operations on organization-managed ciphers, as well as interact with associated attachments. This flaw allows unauthorized individuals to access or modify protected credentials beyond their intended privilege level. Defenders should prioritize updating to the latest patched version to ensure proper access control enforcement.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthorized users to access, modify, or delete organization-wide secrets and attachments. This could lead to massive credential exposure within enterprise Vaultwarden deployments, effectively granting revoked or unvetted users complete control over corporate secrets.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all Vaultwarden instances to a version later than 1.37.3 immediately.</li>
<li>Review organization audit logs for access activity by users with revoked or pending statuses.</li>
<li>Ensure all service accounts and API clients utilizing the Vaultwarden API are patched and audited for abnormal cipher access patterns.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>access-control</category><category>authentication</category></item></channel></rss>