Sploitus

CVE-2026-27803

No indexed exploits for CVE-2026-27803 yet

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations as long as they have access to the collection. This issue has been patched in version 1.35.4.

Affected products
Bitwarden, Vaultwarden
Dani-garcia Vaultwarden
< 1.35.4
Fix
Available
CVSS 3.1
8.3 HIGH
EPSS
0.3% (21th percentile)
Weakness
CWE-863, CWE-285, CWE-269
NVD status
Analyzed
Published
2026-03-04
CVE-2026-27803 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-27803 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-27803 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.