CVE Explorer
CVE-2026-43911
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (password change, KDF change, key rotation, email change, org admin password reset, emergency access takeover). This allows an attacker holding a previously obtained refresh token to maintain session access even after the user has taken action to secure their account. This vulnerability is fixed in 1.35.5
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"vaultwarden","vendor":"dani-garcia","versions":[{"status":"affected","version":"< 1.35.5"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:bde5ff6800c9fb873b418109da19e7046b70ddacc44c9a345fca5363b357392b · sha256:66aeabb15bee6f45… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:bde5ff6800c9fb873b418109da19e7046b70ddacc44c9a345fca5363b357392b · sha256:66aeabb15bee6f45… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-613","description":"CWE-613: Insufficient Session Expiration","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bde5ff6800c9fb873b418109da19e7046b70ddacc44c9a345fca5363b357392b · sha256:66aeabb15bee6f45… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-6j4w-g4jh-xjfx","tags":["x_refsource_CONFIRM"],"url":"https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-6j4w-g4jh-xjfx"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bde5ff6800c9fb873b418109da19e7046b70ddacc44c9a345fca5363b357392b · sha256:66aeabb15bee6f45… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-6j4w-g4jh-xjfx"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bde5ff6800c9fb873b418109da19e7046b70ddacc44c9a345fca5363b357392b · sha256:66aeabb15bee6f45… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.