CVE-2026-95814
Received Received - Intake

Vaultwarden Missing Membership Validation in Cipher Access Queries

Vulnerability report for CVE-2026-95814, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: VulnCheck

Description

Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization ciphers. Attackers with revoked or pending membership can exploit missing status filters in get_user_collections_access_flags, get_group_collections_access_flags, and is_in_full_access_group to access protected cipher data server-side.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vaultwarden vaultwarden 1.37.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Vaultwarden through version 1.37.3 fails to validate organization membership status in three cipher access-restriction queries. This allows users whose membership was revoked or not yet confirmed to retain unauthorized read, write, delete, and attachment access to organization ciphers. The flaw stems from missing status filters in the functions get_user_collections_access_flags, get_group_collections_access_flags, and is_in_full_access_group.

Impact Analysis

If you use Vaultwarden with organization features, attackers or former members could access sensitive cipher data even after revocation or before confirmation. This could lead to data leaks, unauthorized modifications, or deletion of protected information.

Compliance Impact

This vulnerability could violate compliance requirements for data protection and access control, such as GDPR's principle of least privilege or HIPAA's access safeguards. Unauthorized access to sensitive data may result in regulatory penalties or legal consequences.

Mitigation Strategies

Update Vaultwarden to the latest version beyond 1.37.3 to ensure organization membership status validation is enforced in cipher access-restriction queries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95814. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart