CVE-2026-27801: 
Rust vulnerability analysis and mitigation

Overview

CVE-2026-27801 is a two-factor authentication (2FA) bypass vulnerability in Vaultwarden, an unofficial Bitwarden-compatible server written in Rust (formerly bitwarden_rs). Due to faulty rate limit enforcement on protected action OTP validation, an authenticated attacker can brute-force the six-digit one-time passcode and perform privileged actions without completing the 2FA challenge. All versions up to and including 1.34.3 are affected; the issue was disclosed and patched on March 4, 2026, with the release of version 1.35.0. It carries a CVSS v3.1 score of 5.9 (Medium) and a CVSS v4.0 score of 6.0 (Medium) (GitHub Advisory, Vaultwarden Advisory).

Technical details

The root cause is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts). Within the validate_protected_action_otp function, Vaultwarden deserializes OTP attempt data from a JSON blob (pa.data) into a local ProtectedActionData struct, increments the attempt counter on that local copy via pa_data.add_attempt(), but never writes the updated count back to pa.data before calling pa.save(conn) on a failed attempt. As a result, the attempt counter in the database always remains at zero, rendering the six-attempt rate limit completely ineffective. An attacker with a valid authenticated session (JWT token) can exploit this by sending concurrent HTTP POST requests to /api/accounts/api-key (or other protected endpoints) with all 1,000,000 possible six-digit OTP values; from local testing, throughput of up to 2,500 requests per second was achievable, allowing a full brute-force in approximately three minutes (Vaultwarden Advisory, GitHub Advisory).

Impact

A successful exploit allows an authenticated attacker to bypass 2FA protections on all "protected actions" within Vaultwarden, including retrieving the victim user's API key (confidentiality impact) and deleting the user's vault or any organizations where the user holds admin or owner privileges (high integrity impact). Because the API key grants programmatic access to the full vault contents, exploitation could expose all stored credentials and secrets managed by the affected user. There is no direct availability impact, but vault deletion constitutes irreversible data loss (Vaultwarden Advisory, GitHub Advisory).

Exploitability

A complete, runnable Go-language proof-of-concept exploit is publicly available in the official security advisory, demonstrating concurrent brute-forcing of the OTP against the /api/accounts/api-key endpoint (Vaultwarden Advisory). Exploitation requires prior authenticated access to the target account (e.g., via stolen credentials), making it a post-authentication attack with low privileges required. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.038% (3rd percentile), indicating a currently low probability of active exploitation (GitHub Advisory).

Exploitation steps

  1. Obtain authenticated access: Acquire a valid JWT session token for the target Vaultwarden account (e.g., via credential theft, phishing, or credential stuffing against the login endpoint).
  2. Trigger OTP generation: Send an authenticated POST request to /api/accounts/request-otp with the Authorization: Bearer <jwtToken> header to cause Vaultwarden to generate and email a six-digit OTP to the account's registered email address.
  3. Configure the brute-force tool: Set up the published Go PoC script with the target host URL, the obtained jwtToken, desired concurrency (e.g., 100 goroutines), and totalOtps set to 1,000,000 (all possible six-digit values).
  4. Launch concurrent brute-force: Execute the Go script, which spawns concurrent goroutines each testing a non-overlapping range of OTP values (000000–999999) via POST requests to /api/accounts/api-key with payload {"otp": "<candidate>"}. Because the attempt counter is never persisted, the rate limit is never enforced.
  5. Retrieve API key: When the correct OTP is submitted, the server returns HTTP 200 with the user's API key in the response body. The script cancels all remaining goroutines and prints the recovered credentials.
  6. Perform protected actions: Use the recovered API key to access vault contents, or repeat the OTP brute-force against other protected endpoints (e.g., account/organization deletion) to cause data destruction (Vaultwarden Advisory, GitHub Advisory).

Indicators of compromise

  • Network: High volume of POST requests to /api/accounts/api-key, /api/accounts/verify-otp, or /api/accounts/request-otp from a single source IP or small set of IPs in a short time window; request rates exceeding normal user behavior (hundreds to thousands per second).
  • Logs: Vaultwarden access logs showing a large number of HTTP 400 responses to /api/accounts/api-key followed by a single HTTP 200 response, all within a few minutes and sharing the same Authorization header/JWT token; repeated calls to /api/accounts/request-otp from the same session.
  • Application Behavior: OTP validation responses consistently returning "Token is invalid" (rather than "Token has expired") after more than six attempts against the same token, indicating the rate limit is not being enforced (observable in pre-patch versions).
  • Audit Events: Unexpected API key retrieval events or organization/vault deletion events in Vaultwarden audit logs, particularly outside normal business hours or from unusual IP addresses (Vaultwarden Advisory).

Mitigation and workarounds

Upgrade Vaultwarden to version 1.35.0 or later, which fixes the vulnerability by ensuring the attempt counter is correctly persisted to the database (pa.data = pa_data.to_json() before pa.save(conn)) and adds a 20-second delay between OTP requests to enforce time-based rate limiting (Vaultwarden Advisory, GitHub Advisory). For instances that cannot be immediately upgraded, restrict network access to the Vaultwarden instance to trusted networks only, and monitor for anomalous request patterns to the /api/accounts/ endpoints. Enabling strong, unique passwords for all accounts reduces the risk of the prerequisite authenticated access being obtained.

Community reactions

The vulnerability was reported by security researcher d-xuan, with remediation reviewed by BlackDex and verified by dani-garcia (the project maintainer), reflecting a coordinated disclosure process within the Vaultwarden project (Vaultwarden Advisory). Red Hat tracked the issue via Bugzilla (Bug 2444677) and assigned it medium severity, noting the potential for unauthorized access and data deletion (Red Hat Bugzilla). Community discussion was noted on Bluesky and CVE tracking feeds shortly after disclosure, and the advisory was indexed by GitLab's advisory database and ENISA's EUVD (EUVD-2026-9501).

Additional resources


Source: This report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-6w6g-hm98-mhgmHIGH8.7
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-5j98-2g5x-46v6HIGH7.5
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-cjcg-cxmh-9wcrHIGH7.5
  • Rust logoRust
  • praxis-proxy
NoYesOct 02, 2026
GHSA-6f2x-v7q7-m7m5MEDIUM6.9
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-6g2r-675j-hx59LOW2.3
  • Rust logoRust
  • xxhash-rust
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management