CVE-2024-39924 affects Vaultwarden (formerly Bitwarden_RS) 1.30.3. The vulnerability is in the authentication and authorization handling for the endpoint that modifies emergency access metadata. An attacker who has already been granted emergency access can abuse this endpoint to alter security-relevant properties of that emergency access relationship, specifically the access level and the wait time. By changing the access level from a more limited permission set to full control, and by modifying the wait period, the attacker can bypass the intended approval delay and obtain broader access than originally granted. In effect, the flaw allows unauthorized modification of an object associated with the attacker’s emergency access relationship, resulting in privilege escalation within the target vault.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) and lab environment for exploiting CVE-2024-39924, a privilege escalation vulnerability in Vaultwarden (formerly Bitwarden_RS) version 1.30.3. The vulnerability allows an attacker with emergency access to escalate their privileges and bypass the configured wait time, gaining full control over another user's vault. The repository contains a Dockerfile that builds a pre-configured Vaultwarden environment with two users (Susan and Robert), custom SSL certificates, and a pre-set emergency access relationship. The README.md details the exploitation steps, which involve sending a crafted PUT request to the /api/emergency-access/<UUID> endpoint with a JSON body that sets 'waitTimeDays' to 0. After a short cron interval, the attacker (Susan) gains access to Robert's vault. The repository does not contain exploit code per se, but rather a lab setup and detailed instructions for manual exploitation via HTTP requests. No detection scripts or fake exploits are present. The main attack vector is network-based, targeting the Vaultwarden API over HTTPS. Several endpoints and file paths are fingerprintable, including the API endpoint, local web interface, and SSL certificate/key locations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.