* Wed Jun 3 2026 Jonathan Wright - 2026.4.1-1 - update to 2026.4.1 rhbz#2387335 - Fixes CVE-2026-27803 Unauthorized collection management operations due to improper access control - Fixes CVE-2026-27801 Two-factor authentication bypass allows unauthorized access and data deletion - Fixes CVE-2026-27802 Privilege Escalation via Unauthorized Bulk Permission Update - Fixes CVE-2026-27898 Information disclosure via API partial update * Sat Jan 17 2026 Fedora Release Engineering - 2025.7.0-2 - Rebuilt for
* Wed Jun 3 2026 Jonathan Wright - 2026.4.1-1 - update to 2026.4.1 rhbz#2387335 - Fixes CVE-2026-27803 Unauthorized collection management operations due to improper access control - Fixes CVE-2026-27801 Two-factor authentication bypass allows unauthorized access and data deletion - Fixes CVE-2026-27802 Privilege Escalation via Unauthorized Bulk Permission Update - Fixes CVE-2026-27898 Information disclosure via API partial update * Sat Jan 17 2026 Fedora Release Engineering - 2025.7.0-2 - Rebuilt for
[ 1 ] Bug #2444912 - CVE-2026-27898 vaultwarden-web: Vaultwarden: Information disclosure via API partial update [fedora-43] [ 2 ] Bug #2444947 - CVE-2026-27801 vaultwarden-web: Vaultwarden: Two-factor authentication bypass allows unauthorized access and data deletion. [fedora-43] [ 3 ] Bug #2444953 - CVE-2026-27802 vaultwarden-web: Vaultwarden: Privilege Escalation via Unauthorized Bulk Permission Update [fedora-43]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-064873552d' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
