Impact
Vaultwarden versions prior to 1.35.5 expose a flaw that allows an authenticated user who has accepted an organization‑owner invitation but has not yet been confirmed to delete every cipher and attachment in the organization vault. The vulnerability resides in the POST /api/ciphers/purge endpoint, which validates only the ownership role and disregards the confirmation status. The consequence is catastrophic data loss for the entire organization, potentially affecting all members and disrupting service availability.
Affected Systems
The affected product is Vaultwarden by dani‑garcia. All installations running a version earlier than 1.35.5 are susceptible. The issue pertains to the organization owner invitation workflow and does not extend to regular users or other roles.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker requires authentication as an invited, unconfirmed organization owner – a common scenario during normal onboarding. Once authorized, the attacker can invoke the vulnerable endpoint to eradicate all organizational data, making this flaw highly exploitable in environments where unconfirmed owners are present.
OpenCVE Enrichment