CVE-2026-27801 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible…
Medium CVSS: 6.0

CVE-2026-27801

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authenticated access to a user’s account can exploit this bypass to perform protected actions such as accessing the user’s API key or deleting the user’s vault and organisations the user is an admin/owner of . This issue has been patched in version 1.35.0.
Vendor
Dani-garcia
Product
Vaultwarden
CWE
CWE-307
Yayın Tarihi
2026-03-04 22:16:17
Güncelleme
2026-03-06 19:45:34
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar