CVE-2026-43914Dani-garcia · Vaultwarden
Vulnerability data via NVD (ingested)
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is enabled. If email 2fa is enabled, the unprotected 2fa-function send_email_login (email.rs, api endpoint /api/two-factor/send-email-login) also acts as an oracle determining whether a username-password combination is correct. An attacker can abuse that endpoint to brute-force passwords without rate-limiting. This works even for users who don't have email 2fa configured. This vulnerability is fixed in 1.35.4.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-43914product:"Dani-garcia Vaultwarden"http.html:"Vaultwarden"More intel sources (5)
vuln:CVE-2026-43914vulnerabilities.cve_id: CVE-2026-43914CVE-2026-43914CVE-2026-43914"CVE-2026-43914" exploit -site:nvd.nist.gov