Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-0516

NIXPKGS-2026-0516
published on
Permalink CVE-2026-27803
8.3 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): LOW
updated 2 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package vaultwarden-webvault
  • @LeSuisse accepted
  • @LeSuisse deleted
    2 maintainers
    • @dotlambda
    • @SuperSandro2000
    maintainer.delete
  • @LeSuisse published on GitHub
Vaultwarden: Collection Management Operations Allowed Without `manage` Verification for Manager Role

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations as long as they have access to the collection. This issue has been patched in version 1.35.4.

Affected products

vaultwarden
  • ==< 1.35.4

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Ignored maintainers (2)
Upstream advisory: https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-h4hq-rgvh-wh27