28,681 Entries 2,229 Sources 5 Verticals Last sync 12 minutes Live
Dashboard/ Self-hosted apps/ Vaultwarden
Self-hosted apps

Vaultwarden

Vaultwarden
1.36.0 bewährt latest release
03.05.2026

bewährt — keine offenen Regressionen, etabliert · 8 open bugs, 0 Regressions

Upgrade assessment

Sicherheitsrelevant

Zeitnah aktualisieren

19 CVE(s) zuletzt, höchste Schwere: hoch
8 offene Bug-Tickets

Derived automatically from release, repo and CVE data — no judgment by a language model.

Specsattributes
health{'open_bugs': 8, 'checked_at': '2026-06-08T02:00:45.888793', 'open_regressions': 0}
gh_etagW/"ebe62e58eb032dcbf92dbc3bfd04faea1633bb54a9469109e9dc991b13b117d2"
gh_checked_at2026-06-08T03:30:00.101068+00:00
Timelinealle Einträge
Type Ereignis · Quelle Value · Time
CVE
Self-hosted apps High

A vulnerability in Vaultwarden allows attackers with admin rights in one organization to modify or delete groups in other organizations if they know the relevant UUIDs. This can lead to denial of service or privilege escalation.

CVE-2024-56335
06.06.2026
CVE
Self-hosted apps High

A vulnerability in Vaultwarden allows attackers to gain administrator privileges in foreign organizations by manipulating URL parameters while exploiting their own organization rights.

CVE-2025-24365
06.06.2026
CVE
Self-hosted apps High

A vulnerability in Vaultwarden allows attackers with admin access to execute arbitrary code on the server by manipulating configuration settings and uploading specially crafted files.

CVE-2025-24364
06.06.2026
CVE
Self-hosted apps High

A vulnerability in Vaultwarden allows attackers to modify administrator settings without authorization through malicious web pages when the DISABLE_ADMIN_TOKEN option is enabled.

Advisory
06.06.2026
CVE
Self-hosted apps Medium

Vaultwarden password manager up to version 1.34.3 has a two-factor authentication flaw that allows attackers with account access to bypass the six-digit one-time code through repeated attempts and perform protected actions like account deletion.

CVE-2026-27801
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Vaultwarden allows organization members to retrieve all encrypted passwords and data from the organization, even when they should not have access to certain collections.

CVE-2026-26012
06.06.2026
CVE
Self-hosted apps High

A vulnerability in Vaultwarden allows Manager accounts to escalate their privileges and gain unauthorized access to collections not originally assigned to them by exploiting a specific API function.

CVE-2026-27802
06.06.2026
CVE
Self-hosted apps High

Vaultwarden password manager allows users with Manager role to edit and delete collections even when their permission to manage them is explicitly disabled, potentially leading to unauthorized access and data loss.

CVE-2026-27803
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Vaultwarden allows authenticated users to retrieve encrypted password data and attachments belonging to other users through a flawed API endpoint, even though they lack proper authorization.

CVE-2026-27898
06.06.2026
CVE
Self-hosted apps High

A vulnerability in Vaultwarden's SSO login allowed attackers to take over other users' accounts by tricking victims into authenticating through an attacker-controlled login process.

CVE-2026-47158
06.06.2026
CVE
Self-hosted apps Medium

An authorization flaw in Vaultwarden allows managers with restricted permissions to view names and assignments of all collections in their organization, even though they should only access specific collections assigned to them.

CVE-2026-33420
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Vaultwarden allows attackers with password access to permanently corrupt WebAuthn credentials by sending fake authentication data that gets processed before signature verification, potentially causing permanent denial of two-factor authentication service.

CVE-2026-31835
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Vaultwarden allows attackers to discover which organizations use SSO by submitting arbitrary email addresses, then obtain valid authentication tokens without proving identity ownership.

CVE-2026-47159
06.06.2026
CVE
Self-hosted apps Medium

A security vulnerability in Vaultwarden allows attackers to maintain account access using old refresh tokens even after users perform security-sensitive actions like password changes.

CVE-2026-43911
06.06.2026
CVE
Self-hosted apps High

A vulnerability in Vaultwarden allowed attackers to impersonate other users by registering an identity with the victim's email address at an Identity Provider and exploiting insufficient email verification in the SSO login process.

CVE-2026-47164
06.06.2026
CVE
Self-hosted apps High

Vaultwarden, a password manager, fails to properly verify that groups and users belong to the same organization, allowing administrators of one organization to gain unauthorized access to passwords and data from other organizations.

CVE-2026-43912
06.06.2026
CVE
Self-hosted apps High

A security vulnerability in Vaultwarden allows invited organization owners to delete the entire organization vault before their invitation is confirmed by existing owners, potentially causing immediate data loss.

CVE-2026-43913
06.06.2026
CVE
Self-hosted apps High

Vaultwarden before version 1.35.4 has a vulnerability that allows attackers to bypass brute-force protection when email 2FA is enabled, enabling password guessing without rate limiting.

CVE-2026-43914
06.06.2026
CVE
Self-hosted apps Medium

Vaultwarden, a password manager, has a vulnerability in its icon fetching feature that allows attackers to send HTTP requests to internal servers by using IP addresses in alternative formats (decimal, hexadecimal) to bypass security filters.

CVE-2026-47160
06.06.2026
REL
Self-hosted apps Critical bewährt

Critical security fixes for SSO CSRF, user enumeration, SSRF and other vulnerabilities plus new item archiving feature

1.36.0
03.05.2026
REL
Self-hosted apps Medium bewährt

Bug fixes for master password policies, recovery codes, refresh token responses and DNS issues along with updates for Rust, dependencies and web vault

1.35.8
25.04.2026
REL
Self-hosted apps Medium bewährt

Fixes an issue with two-factor authentication on Android devices

1.35.7
13.04.2026
REL
Self-hosted apps Critical bewährt

Critical security fixes for organization management and token invalidation, admin templates changed, 2FA tokens limited to 30 days

1.35.5
12.04.2026
REL
Self-hosted apps High bewährt

Fixes critical bug in two-factor authentication where remember tokens and recovery tokens were not accepted

1.35.6
12.04.2026
REL
Self-hosted apps Critical bewährt

Security update fixes critical vulnerabilities in cipher access and organization permissions

1.35.4
23.02.2026
REL
Self-hosted apps High bewährt

Security update fixes critical vulnerability allowing authenticated attackers to access organization collections they don't belong to

1.35.3
10.02.2026
REL
Self-hosted apps Medium bewährt

Fixes critical organization creation bug in web-vault and improves Android compatibility and SSO functionality

1.35.2
09.01.2026
REL
Self-hosted apps Medium bewährt

Fixes logout issue after upgrade caused by refresh token parsing error and updates web vault to version 2025.12.1

1.35.1
30.12.2025
REL
Self-hosted apps Medium bewährt

Vaultwarden 1.35.0 introduces OpenID Connect SSO support, updates web vault to 2025.12.0, and fixes various bugs in multi-select push and WebAuthn functionality

1.35.0
27.12.2025
REL
Self-hosted apps Medium bewährt

Fixes MySQL/MariaDB connection issues in Alpine images by downgrading to MariaDB Connector/C v3.4.5

1.34.3
30.07.2025
REL
Self-hosted apps Low bewährt

Vaultwarden 1.34.2 updates web vault to 2025.7.0, adds experimental S3 support and fixes various issues with passkeys, password policies and Yubico keys

1.34.2
27.07.2025
REL
Self-hosted apps Medium bewährt

Vaultwarden 1.34.0 introduces new registration flow with email verification, fixes CVE-2025-25188, and adds feature flags for mTLS and attachment export

1.34.0
26.05.2025
REL
Self-hosted apps Medium bewährt

Fixes a crash in the admin diagnostics functionality

1.34.1
26.05.2025
REL
Self-hosted apps Medium bewährt

Security update with CVE fix, workflow improvements and bug fixes for icon redirects and collection management

1.33.2
09.02.2025
REL
Self-hosted apps Low bewährt

Bugfix release with corrections for desktop client icons, invitations, DUO settings, manager rights and mobile client synchronization

1.33.1
03.02.2025
REL
Self-hosted apps Critical Breaking

Security update fixing three critical vulnerabilities, manager roles converted to custom roles, and web-vault updated to v2025.1.1

1.33.0
25.01.2025
REL
Self-hosted apps High bewährt

Security update fixes critical vulnerability when ORG_GROUPS_ENABLED setting is enabled and includes additional optimizations

1.32.7
20.12.2024
REL
Self-hosted apps Medium bewährt

Bug fixes for push notifications, member management and sync issues with native clients plus backend admin updates

1.32.6
10.12.2024
REL
Self-hosted apps High bewährt

Security update with CVE fixes, SSH key support for desktop clients and various bug fixes

1.32.5
18.11.2024
REL
Self-hosted apps High bewährt

Security update fixes multiple CVE vulnerabilities and improves mobile app compatibility

1.32.4
10.11.2024
REL
Self-hosted apps Medium bewährt

Bug fixes for email invitations, SMTP issues with certain providers, iOS synchronization and collection management

1.32.3
27.10.2024
REL
Self-hosted apps Low bewährt

Bug fixes for collection management, Windows compilation and version parameter

1.32.2
13.10.2024
REL
Self-hosted apps Medium bewährt

Bugfix release with fixes for mobile client synchronization, new SQLite backup CLI option and email template improvements

1.32.1
03.10.2024
REL
Self-hosted apps Critical bewährt

Security update with fixes for three CVE vulnerabilities, web-vault update and various bug fixes

1.32.0
11.08.2024
REL
Self-hosted apps Medium Breaking

Removes WebSocket support on port 3012, adds support for new mobile apps and updates web vault to version 2024.5.1

1.31.0
08.07.2024
REL
Self-hosted apps Medium Breaking

WebSocket service for live sync integrated into main HTTP server, separate port 3012 is deprecated and will be removed in next release

1.30.4
02.03.2024
REL
Self-hosted apps Low bewährt

Bug fix for web API call compatibility with jQuery 3.7.1

1.30.5
02.03.2024
REL
Self-hosted apps Medium Breaking

Fixes issues with push notifications and Docker healthcheck, WebSocket service integrated into main server and separate port 3012 will be removed in next release

1.30.3
01.02.2024
REL
Self-hosted apps Medium Breaking

WebSocket service integrated into main HTTP server, old port 3012 is deprecated and will be removed in next release

1.30.2
30.01.2024