Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-h4hq-rgvh-wh27 | Vaultwarden's Collection Management Operations Allowed Without `manage` Verification for Manager Role |
Fri, 06 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:dani-garcia:vaultwarden:*:*:*:*:*:*:*:* |
Thu, 05 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 05 Mar 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dani-garcia
Dani-garcia vaultwarden |
|
| Vendors & Products |
Dani-garcia
Dani-garcia vaultwarden |
Wed, 04 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations as long as they have access to the collection. This issue has been patched in version 1.35.4. | |
| Title | Vaultwarden: Collection Management Operations Allowed Without `manage` Verification for Manager Role | |
| Weaknesses | CWE-269 CWE-285 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-05T15:42:36.935Z
Reserved: 2026-02-24T02:31:33.266Z
Link: CVE-2026-27803
Updated: 2026-03-05T15:32:47.918Z
Status : Analyzed
Published: 2026-03-04T22:16:18.210
Modified: 2026-03-06T19:45:27.070
Link: CVE-2026-27803
OpenCVE Enrichment
Updated: 2026-04-16T13:15:06Z
Github GHSA