Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization ciphers. Attackers with revoked or pending membership can exploit missing status filters in get_user_collections_access_flags, get_group_collections_access_flags, and is_in_full_access_group to access protected cipher data server-side. | |
| Title | Vaultwarden through 1.37.3 Authorization Bypass via Missing Status Check | |
| First Time appeared |
Dani-garcia
Dani-garcia vaultwarden |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:dani-garcia:vaultwarden:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dani-garcia
Dani-garcia vaultwarden |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-22T20:21:13.488Z
Reserved: 2026-09-22T15:47:13.821Z
Link: CVE-2026-95814
No data.
Status : Received
Published: 2026-09-22T21:17:34.417
Modified: 2026-09-22T21:17:34.417
Link: CVE-2026-95814
No data.
OpenCVE Enrichment
Updated: 2026-09-22T21:30:20Z
-
CWE-863
Incorrect Authorization