PT-2026-56552 · Bitwarden · Bitwarden Server

·

CVE-2026-60104

·

Published

2026-07-08

·

Updated

2026-07-20

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Bitwarden Server versions prior to 2026.6.0
Description An issue exists where the server fails to verify if the email address provided in the body of the 'POST /auth-requests/admin-request' endpoint belongs to the authenticated user. This allows a low-privileged organization member to initiate a Trusted Device Encryption authentication request bound to a public key controlled by the attacker. Once approved, the request becomes readable from an unauthenticated endpoint, enabling the attacker to obtain another user's vault key and a victim-scoped access token, leading to account takeover and disclosure of the vault key.
Recommendations Update Bitwarden Server to version 2026.6.0 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60104

Affected Products

Bitwarden Server