Authorization bypass through user-controlled key in keepassxc - #VU151870
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to authorization bypass through a user-controlled key in the KeePassXC-Browser extension when saving login credentials containing references to other entries. A remote attacker can cause a website to save a username or password field as references to other entry data and receive the referenced data when credentials are filled.
User interaction is required to save the login credentials or fill them in; automatic filling can also trigger disclosure.