Vaultwarden is no longer asking me to 2FA/MFA when signing in. #1196

Closed
opened 2026-04-06 01:41:29 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @alternativesurfer on 3/12/2024

Subject of the issue

I signed into Vaultwarden today and was not prompted for my 2FA code.
I signed in to the full vault without having to provide a second factor.

Deployment environment

  • vaultwarden version:
  • Install method:

  • Clients used:
    Web/Edge app/Android app

  • Reverse proxy and version:
    HAProxy

  • MySQL/MariaDB or PostgreSQL version:
    postgresql

  • Other relevant details:

Steps to reproduce

I launched my browser, signed into the browser addon (https://microsoftedge.microsoft.com/addons/detail/jbkfoedolllekgbhcbcoahefnbanhhlh) and was allowed to access my vault without entering 2FA.

I confirmed I have multiple 2FA types enabled.

I then tested from the browser window, same behavior.

Expected behaviour

Actual behaviour

Troubleshooting data

*Originally created by @alternativesurfer on 3/12/2024* <!-- # ### NOTE: Please update to the latest version of vaultwarden before reporting an issue! This saves you and us a lot of time and troubleshooting. See: * https://github.com/dani-garcia/vaultwarden/issues/1180 * https://github.com/dani-garcia/vaultwarden/wiki/Updating-the-vaultwarden-image # ### --> <!-- Please fill out the following template to make solving your problem easier and faster for us. This is only a guideline. If you think that parts are unnecessary for your issue, feel free to remove them. Remember to hide/redact personal or confidential information, such as passwords, IP addresses, and DNS names as appropriate. --> ### Subject of the issue <!-- Describe your issue here. --> I signed into Vaultwarden today and was not prompted for my 2FA code. I signed in to the full vault without having to provide a second factor. ### Deployment environment <!-- ========================================================================================= Preferably, use the `Generate Support String` button on the admin page's Diagnostics tab. That will auto-generate most of the info requested in this section. ========================================================================================= --> <!-- The version number, obtained from the logs (at startup) or the admin diagnostics page --> <!-- This is NOT the version number shown on the web vault, which is versioned separately from vaultwarden --> <!-- Remember to check if your issue exists on the latest version first! --> * vaultwarden version: <!-- How the server was installed: Docker image, OS package, built from source, etc. --> * Install method: * Clients used: <!-- web vault, desktop, Android, iOS, etc. (if applicable) --> Web/Edge app/Android app * Reverse proxy and version: <!-- if applicable --> HAProxy * MySQL/MariaDB or PostgreSQL version: <!-- if applicable --> postgresql * Other relevant details: ### Steps to reproduce <!-- Tell us how to reproduce this issue. What parameters did you set (differently from the defaults) and how did you start vaultwarden? --> I launched my browser, signed into the browser addon (https://microsoftedge.microsoft.com/addons/detail/jbkfoedolllekgbhcbcoahefnbanhhlh) and was allowed to access my vault without entering 2FA. I confirmed I have multiple 2FA types enabled. I then tested from the browser window, same behavior. ### Expected behaviour <!-- Tell us what you expected to happen --> ### Actual behaviour <!-- Tell us what actually happened --> ### Troubleshooting data <!-- Share any log files, screenshots, or other relevant troubleshooting data -->
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/vaultwarden#1196