Skip to main content

Vendor/product archive

bitwarden / server CVEs

Beta · best-effort

9 CVEs tagged to bitwarden / server1 Critical, 5 High, 2 Medium, 1 Low, 0 Unrated.

CVE-2026-60104

Published Jul 8, 2026

Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organiza…

CVSS 9.3 · Critical
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-57522

Published Jun 25, 2026

Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integ…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-57521

Published Jun 25, 2026

Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an ar…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-57520

Published Jun 25, 2026

Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an…

CVSS 7.1 · High
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-43640

Published May 11, 2026

Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user w…

CVSS 8.6 · High
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-43639

Published May 11, 2026

Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST…

CVSS 8.9 · High
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-43638

Published May 11, 2026

Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /ci…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2020-15879

Published Jul 21, 2020

Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1