PatchSiren

bitwarden CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM bitwarden CVE published 2026-08-10

CVE-2026-71959

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T14:17:26.870Z and has not been modified since then. This vulnerability affects Bitwarden Server deployments, allowing authenticated users to forge audit log entries. Defenders should assess exposure and prioritize verification and potential upgrades. The CVE record and NVD entry provide details o [truncated]

CRITICAL bitwarden CVE published 2026-07-08

CVE-2026-60104

CVE-2026-60104 is a critical vulnerability in Bitwarden Server before version 2026.6.0. The issue allows a low-privileged organization member to obtain another user's vault key and a victim-scoped access token. This is achieved by creating a Trusted Device Encryption authentication request bound to an attacker-controlled public key. The request is readable from an unauthenticated endpoint once approved, r [truncated]

HIGH Bitwarden CVE published 2026-05-11

CVE-2026-43640

CVE-2026-43640 is a high-severity vulnerability in Bitwarden Server prior to v2026.4.1, allowing an authenticated user with SCIM management privileges to obtain the organization's SCIM API key without requiring master-password re-authentication. This vulnerability has significant implications for Bitwarden Server administrators and users with SCIM management privileges, as it could lead to unauthorized ac [truncated]

HIGH Bitwarden CVE published 2026-05-11

CVE-2026-43639

CVE-2026-43639 debrief: Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{providerId}/clients/existing`, resulting in takeover of the target organization. The vulnerability has a CVSS score of 8.9 and is classified as HIGH severity. Self-hosted installations are unaffected.

MEDIUM Bitwarden CVE published 2026-05-11

CVE-2026-43638

CVE-2026-43638 is a missing authorization vulnerability in Bitwarden Server prior to v2026.4.1. An authenticated user can write ciphers into an arbitrary organization via `POST /ciphers/import-organization` by submitting an empty `collections` array, which causes the server-side permission check to be skipped. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The vulnerability was patch [truncated]