Critical Security Flaws in Vaultwarden Affecting Fedora 43 and 44

Critical Security Flaws in Vaultwarden Affecting Fedora 43 and 44

4h ago Linuxsecurity 89% similarity 72.6
Share:

Article Content

Browse articles
ThreatCluster

Multiple critical vulnerabilities have been identified in Vaultwarden, impacting Fedora 43 and 44. Key issues include CVE-2026-27801, allowing two-factor authentication bypass, and CVE-2026-27803, which enables unauthorized collection management operations. These vulnerabilities could lead to unauthorized access and data deletion. The updates released on June 3, 2026, address these flaws, along with several others, including CVE-2026-25537 and CVE-2026-26012, which involve authorization bypass and denial of service attacks. Users are urged to apply the updates promptly to mitigate risks. The vulnerabilities were disclosed between February and March 2026, with some having proof-of-concept (PoC) exploits available. The affected systems include Vaultwarden installations on Fedora platforms.

Key Points: • Critical vulnerabilities in Vaultwarden could allow unauthorized access and data deletion. • CVE-2026-27801 and CVE-2026-27803 are among the most severe flaws addressed in recent updates. • Users must update their Vaultwarden installations on Fedora 43 and 44 to protect against these threats.

ThreatCluster AI

Timeline

2025-08-29
CVE-2025-58160 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-02-04
CVE-2026-25537 published
A type confusion vulnerability in jsonwebtoken could lead to authorization bypass.
Linuxsecurity
2026-02-06
CVE-2026-25727 published
A denial of service vulnerability due to stack exhaustion was disclosed.
Linuxsecurity
2026-02-11
CVE-2026-26012 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-04
CVE-2026-27801, CVE-2026-27803, CVE-2026-27802, CVE-2026-27898 published
Multiple vulnerabilities were disclosed, including two-factor authentication bypass and unauthorized collection management.
Linuxsecurity
2026-06-03
Updates released for Vaultwarden
Critical updates addressing multiple CVEs were released for Vaultwarden on Fedora 43 and 44.
Linuxsecurity
2026-06-12
Security advisories published
Linuxsecurity published advisories detailing the critical vulnerabilities in Vaultwarden.
Linuxsecurity

Community

Browse all →