CVE Tools

Vaultwarden

25 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Vaultwarden, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Vaultwarden CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Vaultwarden CVEs per month
MonthCVEs
2024-100
2024-110
2024-121
2025-015
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-021
2026-034
2026-040
2026-056
2026-060
2026-074
2026-080
2026-091

Severity

How the 25 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical29%
  • High1252%
  • Medium939%

Latest CVEs

The 15 most recently published vulnerabilities affecting Vaultwarden.

  1. CVE-2026-95814Vaultwarden through 1.37.3 Authorization Bypass via Missing Status Check8.1
  2. CVE-2026-47160Vaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex/Octal IP Bypass5.8
  3. CVE-2026-47164Vaultwarden: SSO Email Auto-Link Can Bind an Existing Local Account to an Attacker-Controlled IdP Identity7.7
  4. CVE-2026-47159Vaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token Exposure—
  5. CVE-2026-47158Vaultwarden: CSRF in SSO Authorization Flow8.3
  6. CVE-2026-43914Vaultwarden: Brute-force protection bypass vulnerability7.3
  7. CVE-2026-43913Vaultwarden: Unconfirmed Owner Can Purge Entire Organization Vault8.1
  8. CVE-2026-43912Vaultwarden: Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Another Organization8.7
  9. CVE-2026-43911Vaultwarden: Refresh tokens not invalidated on security stamp rotation6.8
  10. CVE-2026-33420Vaultwarden missing authorization check allows Manager-role users to enumerate all collections5.3
  11. CVE-2026-31835Vaultwarden WebAuthn credential metadata tampered before signature verification5.4
  12. CVE-2026-27898Vaultwarden: Unauthorized Access via Partial Update API on Another User’s Cipher5.4
  13. CVE-2026-27803Vaultwarden: Collection Management Operations Allowed Without `manage` Verification for Manager Role8.3
  14. CVE-2026-27802Vaultwarden: Privilege Escalation via Bulk Permission Update to Unauthorized Collections by Manager8.3
  15. CVE-2026-27801Vaultwarden: 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store