
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26012 is a broken access control vulnerability in vaultwarden, an unofficial Bitwarden-compatible server written in Rust (formerly bitwarden_rs). It allows any authenticated organization member to retrieve all ciphers within an organization, bypassing collection-level permissions. All versions prior to 1.35.3 are affected. The vulnerability was disclosed on February 11, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is Incorrect Authorization (CWE-863) combined with Insufficient Granularity of Access Control (CWE-1220). The vulnerable endpoint /ciphers/organization-details is accessible to any organization member and internally calls Cipher::find_by_org, which retrieves all ciphers for the organization without filtering by the requesting user's collection membership. Ciphers are returned using CipherSyncType::Organization with no enforcement of collection-level access controls, meaning the authorization check is performed at the organization level but not at the collection level. Exploitation requires only a valid session token for an account that is a member of the target organization (User, Manager, Admin, or Owner role) (GitHub Advisory).
A successful exploit results in unauthorized disclosure of all encrypted cipher data, cryptographic keys, and attachment metadata stored within an organization, regardless of the attacker's assigned collection permissions. This effectively nullifies collection-based access separation, which is the primary data isolation mechanism within vaultwarden organizations. If the attacker can perform client-side decryption (e.g., by possessing the organization's encryption key), the exposure escalates to full plaintext credential disclosure for all organization members' vaulted secrets (GitHub Advisory, Red Hat Bugzilla).
A public proof-of-concept exploit is available on GitHub at https://github.com/Dulieno/CVE-2026-26012, published around March 2, 2026. There is no confirmed evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.023% (0.000230), indicating a currently low probability of widespread exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly, PoC GitHub).
/ciphers/organization-details with the target organization's ID as a query parameter (e.g., GET /api/ciphers/organization-details?organizationId=<ORG_UUID>)./api/ciphers/organization-details or /ciphers/organization-details from accounts that are low-privileged organization members, especially if the account does not normally access this endpoint or accesses it for organizations outside their typical scope.organization-details endpoint from accounts with restricted collection memberships; large response payloads returned to accounts that should only have access to a subset of ciphers.The vulnerability is fixed in vaultwarden version 1.35.3, released February 10, 2026. All administrators should upgrade immediately (vaultwarden Release). For instances that cannot be patched immediately, consider implementing network-level or reverse-proxy access controls to restrict access to the /ciphers/organization-details endpoint to trusted IP ranges only. Additionally, audit organization membership logs for suspicious access patterns and remove unnecessary members from organizations to reduce the attack surface (GitHub Advisory).
The vaultwarden maintainer (BlackDex) was credited as the remediation developer, and the reporter was identified as odgrso in the GitHub security advisory. The release of version 1.35.3 received strong community engagement on GitHub, with 122 reactions including thumbs-up and heart emojis, reflecting the active self-hosted community's appreciation for the prompt fix. CyberHub Blog published an article titled "Vulnerability in Vaultwarden Exposes Encrypted Passwords," indicating moderate media coverage in the self-hosted and open-source security community (GitHub Advisory, vaultwarden Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."