Skip to main content

Vendor archive

bitwarden CVEs

Beta · best-effort

14 CVEs tagged to vendor bitwarden1 Critical, 9 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2026-60104

Published Jul 8, 2026

Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organiza…

CVSS 9.3 · Critical
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-57522

Published Jun 25, 2026

Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integ…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-57521

Published Jun 25, 2026

Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an ar…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-57520

Published Jun 25, 2026

Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an…

CVSS 7.1 · High
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-43640

Published May 11, 2026

Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user w…

CVSS 8.6 · High
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-43639

Published May 11, 2026

Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST…

CVSS 8.9 · High
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-43638

Published May 11, 2026

Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /ci…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-42994

Published May 1, 2026

Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx supply chain incident.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-38840

Published Aug 15, 2023

Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27706

Published Jun 9, 2023

Bitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, accessible to other local unprivileged processes.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27974

Published Mar 9, 2023

Bitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for an example.com hosting provider when customer-website.exampl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-25081

Published Mar 9, 2023

Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element. NOTE: the vendor's position is that there have been important legitimate cross-domain co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15879

Published Jul 21, 2020

Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1