PT-2026-39863 · Unknown · Vaultwarden

·

CVE-2026-43913

·

Published

2026-05-11

·

Updated

2026-05-12

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vaultwarden versions prior to 1.35.5
Description Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The issue exists because the 'POST /api/ciphers/purge' endpoint verifies that a user has the Owner membership type but fails to verify that the membership status is Confirmed. Consequently, an authenticated user who has accepted an organization owner invite but has not yet been confirmed by an existing owner can call this endpoint to permanently delete all ciphers and attachments within the organization, leading to immediate data loss.
Recommendations Update to version 1.35.5.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43913
GHSA-937X-3J8M-7W7P

Affected Products

Vaultwarden