PT-2026-56552 · Bitwarden · Bitwarden Server
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Bitwarden Server versions prior to 2026.6.0
Description
An issue exists where the server fails to verify if the email address provided in the body of the 'POST /auth-requests/admin-request' endpoint belongs to the authenticated user. This allows a low-privileged organization member to initiate a Trusted Device Encryption authentication request bound to a public key controlled by the attacker. Once approved, the request becomes readable from an unauthenticated endpoint, enabling the attacker to obtain another user's vault key and a victim-scoped access token, leading to account takeover and disclosure of the vault key.
Recommendations
Update Bitwarden Server to version 2026.6.0 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bitwarden Server