CVE-2026-26012: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-26012 is a broken access control vulnerability in vaultwarden, an unofficial Bitwarden-compatible server written in Rust (formerly bitwarden_rs). It allows any authenticated organization member to retrieve all ciphers within an organization, bypassing collection-level permissions. All versions prior to 1.35.3 are affected. The vulnerability was disclosed on February 11, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is Incorrect Authorization (CWE-863) combined with Insufficient Granularity of Access Control (CWE-1220). The vulnerable endpoint /ciphers/organization-details is accessible to any organization member and internally calls Cipher::find_by_org, which retrieves all ciphers for the organization without filtering by the requesting user's collection membership. Ciphers are returned using CipherSyncType::Organization with no enforcement of collection-level access controls, meaning the authorization check is performed at the organization level but not at the collection level. Exploitation requires only a valid session token for an account that is a member of the target organization (User, Manager, Admin, or Owner role) (GitHub Advisory).

Impact

A successful exploit results in unauthorized disclosure of all encrypted cipher data, cryptographic keys, and attachment metadata stored within an organization, regardless of the attacker's assigned collection permissions. This effectively nullifies collection-based access separation, which is the primary data isolation mechanism within vaultwarden organizations. If the attacker can perform client-side decryption (e.g., by possessing the organization's encryption key), the exposure escalates to full plaintext credential disclosure for all organization members' vaulted secrets (GitHub Advisory, Red Hat Bugzilla).

Exploitability

A public proof-of-concept exploit is available on GitHub at https://github.com/Dulieno/CVE-2026-26012, published around March 2, 2026. There is no confirmed evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.023% (0.000230), indicating a currently low probability of widespread exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly, PoC GitHub).

Exploitation steps

  1. Obtain organization membership: Register or use an existing low-privileged account that is a member of the target vaultwarden organization (any role — User, Manager, Admin, or Owner qualifies).
  2. Authenticate: Log in to the vaultwarden instance and obtain a valid session/bearer token via the standard authentication flow.
  3. Call the vulnerable endpoint: Send an authenticated HTTP GET request to /ciphers/organization-details with the target organization's ID as a query parameter (e.g., GET /api/ciphers/organization-details?organizationId=<ORG_UUID>).
  4. Receive unrestricted cipher data: The server responds with all ciphers in the organization — including those in collections the attacker has no access to — along with encrypted cipher data, keys, and attachment metadata.
  5. Attempt decryption: If the attacker possesses or can derive the organization's symmetric encryption key (e.g., from their own membership data), use the Bitwarden client or custom tooling to decrypt the retrieved cipher data and extract plaintext credentials (GitHub Advisory, PoC GitHub).

Indicators of compromise

  • Network: Unusual or repeated HTTP GET requests to /api/ciphers/organization-details or /ciphers/organization-details from accounts that are low-privileged organization members, especially if the account does not normally access this endpoint or accesses it for organizations outside their typical scope.
  • Logs: Vaultwarden access logs showing requests to the organization-details endpoint from accounts with restricted collection memberships; large response payloads returned to accounts that should only have access to a subset of ciphers.
  • Behavioral: A single user account querying the organization-details endpoint multiple times in a short period, or doing so immediately after joining an organization, may indicate automated exploitation using the PoC tool.

Mitigation and workarounds

The vulnerability is fixed in vaultwarden version 1.35.3, released February 10, 2026. All administrators should upgrade immediately (vaultwarden Release). For instances that cannot be patched immediately, consider implementing network-level or reverse-proxy access controls to restrict access to the /ciphers/organization-details endpoint to trusted IP ranges only. Additionally, audit organization membership logs for suspicious access patterns and remove unnecessary members from organizations to reduce the attack surface (GitHub Advisory).

Community reactions

The vaultwarden maintainer (BlackDex) was credited as the remediation developer, and the reporter was identified as odgrso in the GitHub security advisory. The release of version 1.35.3 received strong community engagement on GitHub, with 122 reactions including thumbs-up and heart emojis, reflecting the active self-hosted community's appreciation for the prompt fix. CyberHub Blog published an article titled "Vulnerability in Vaultwarden Exposes Encrypted Passwords," indicating moderate media coverage in the self-hosted and open-source security community (GitHub Advisory, vaultwarden Release).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management