Impact
An authorization flaw in Vaultwarden allows users who have been revoked from or have a pending membership in an organization to retain full read, write, delete, and attachment rights to organization ciphers. The software incorrectly omits the membership status check in three query paths, enabling unauthorized access to sensitive data. This vulnerability maps to a discretionary access control weakness and permits compromise of confidential information within the organization.
Affected Systems
The issue affects the open‐source Vaultwarden application developed by dani-garcia. Version 1.37.3 and earlier are vulnerable; newer releases have fixed the status validation logic.
Risk and Exploitability
With a CVSS score of 8.6 the vulnerability is classified as high severity. The EPSS score is not available, and the flaw is not currently listed in the CISA KEV catalog. Exploitation requires the attacker to possess a credential for a user with revoked or pending membership; the missing status filters can then be leveraged to access protected cipher data on the server. Given the elevated severity and the need for internal credentials, the risk to organizations with active Vaultwarden deployments is moderate to high.
OpenCVE Enrichment