PT-2026-52574 · Bitwarden · Bitwarden Server
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Bitwarden Server versions prior to 2026.5.0
Description
An issue exists where authenticated Custom users with the
ManageUsers permission can escalate privileges to remove Admin accounts from an organization. This occurs due to a missing role hierarchy check in the bulk user-remove endpoint. By supplying Admin organization-user IDs in a bulk DELETE request, an attacker can bypass the security guards present in the single-user removal path.Recommendations
Update Bitwarden Server to version 2026.5.0 or later.
Exploit
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bitwarden Server