
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27801 is a two-factor authentication (2FA) bypass vulnerability in Vaultwarden, an unofficial Bitwarden-compatible server written in Rust (formerly bitwarden_rs). Due to faulty rate limit enforcement on protected action OTP validation, an authenticated attacker can brute-force the six-digit one-time passcode and perform privileged actions without completing the 2FA challenge. All versions up to and including 1.34.3 are affected; the issue was disclosed and patched on March 4, 2026, with the release of version 1.35.0. It carries a CVSS v3.1 score of 5.9 (Medium) and a CVSS v4.0 score of 6.0 (Medium) (GitHub Advisory, Vaultwarden Advisory).
The root cause is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts). Within the validate_protected_action_otp function, Vaultwarden deserializes OTP attempt data from a JSON blob (pa.data) into a local ProtectedActionData struct, increments the attempt counter on that local copy via pa_data.add_attempt(), but never writes the updated count back to pa.data before calling pa.save(conn) on a failed attempt. As a result, the attempt counter in the database always remains at zero, rendering the six-attempt rate limit completely ineffective. An attacker with a valid authenticated session (JWT token) can exploit this by sending concurrent HTTP POST requests to /api/accounts/api-key (or other protected endpoints) with all 1,000,000 possible six-digit OTP values; from local testing, throughput of up to 2,500 requests per second was achievable, allowing a full brute-force in approximately three minutes (Vaultwarden Advisory, GitHub Advisory).
A successful exploit allows an authenticated attacker to bypass 2FA protections on all "protected actions" within Vaultwarden, including retrieving the victim user's API key (confidentiality impact) and deleting the user's vault or any organizations where the user holds admin or owner privileges (high integrity impact). Because the API key grants programmatic access to the full vault contents, exploitation could expose all stored credentials and secrets managed by the affected user. There is no direct availability impact, but vault deletion constitutes irreversible data loss (Vaultwarden Advisory, GitHub Advisory).
A complete, runnable Go-language proof-of-concept exploit is publicly available in the official security advisory, demonstrating concurrent brute-forcing of the OTP against the /api/accounts/api-key endpoint (Vaultwarden Advisory). Exploitation requires prior authenticated access to the target account (e.g., via stolen credentials), making it a post-authentication attack with low privileges required. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.038% (3rd percentile), indicating a currently low probability of active exploitation (GitHub Advisory).
/api/accounts/request-otp with the Authorization: Bearer <jwtToken> header to cause Vaultwarden to generate and email a six-digit OTP to the account's registered email address.host URL, the obtained jwtToken, desired concurrency (e.g., 100 goroutines), and totalOtps set to 1,000,000 (all possible six-digit values).000000–999999) via POST requests to /api/accounts/api-key with payload {"otp": "<candidate>"}. Because the attempt counter is never persisted, the rate limit is never enforced./api/accounts/api-key, /api/accounts/verify-otp, or /api/accounts/request-otp from a single source IP or small set of IPs in a short time window; request rates exceeding normal user behavior (hundreds to thousands per second)./api/accounts/api-key followed by a single HTTP 200 response, all within a few minutes and sharing the same Authorization header/JWT token; repeated calls to /api/accounts/request-otp from the same session."Token is invalid" (rather than "Token has expired") after more than six attempts against the same token, indicating the rate limit is not being enforced (observable in pre-patch versions).Upgrade Vaultwarden to version 1.35.0 or later, which fixes the vulnerability by ensuring the attempt counter is correctly persisted to the database (pa.data = pa_data.to_json() before pa.save(conn)) and adds a 20-second delay between OTP requests to enforce time-based rate limiting (Vaultwarden Advisory, GitHub Advisory). For instances that cannot be immediately upgraded, restrict network access to the Vaultwarden instance to trusted networks only, and monitor for anomalous request patterns to the /api/accounts/ endpoints. Enabling strong, unique passwords for all accounts reduces the risk of the prerequisite authenticated access being obtained.
The vulnerability was reported by security researcher d-xuan, with remediation reviewed by BlackDex and verified by dani-garcia (the project maintainer), reflecting a coordinated disclosure process within the Vaultwarden project (Vaultwarden Advisory). Red Hat tracked the issue via Bugzilla (Bug 2444677) and assigned it medium severity, noting the potential for unauthorized access and data deletion (Red Hat Bugzilla). Community discussion was noted on Bluesky and CVE tracking feeds shortly after disclosure, and the advisory was indexed by GitLab's advisory database and ENISA's EUVD (EUVD-2026-9501).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."