PatchSiren

Bitwarden CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL bitwarden CVE published 2026-07-08

CVE-2026-60104

CVE-2026-60104 is a critical vulnerability in Bitwarden Server before version 2026.6.0. The issue allows a low-privileged organization member to obtain another user's vault key and a victim-scoped access token. This is achieved by creating a Trusted Device Encryption authentication request bound to an attacker-controlled public key. The request is readable from an unauthenticated endpoint once approved, r [truncated]

HIGH Bitwarden CVE published 2026-05-11

CVE-2026-43640

CVE-2026-43640 is a high-severity vulnerability in Bitwarden Server prior to v2026.4.1, allowing an authenticated user with SCIM management privileges to obtain the organization's SCIM API key without requiring master-password re-authentication. This vulnerability has significant implications for Bitwarden Server administrators and users with SCIM management privileges, as it could lead to unauthorized ac [truncated]

HIGH Bitwarden CVE published 2026-05-11

CVE-2026-43639

CVE-2026-43639 debrief: Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{providerId}/clients/existing`, resulting in takeover of the target organization. The vulnerability has a CVSS score of 8.9 and is classified as HIGH severity. Self-hosted installations are unaffected.

MEDIUM Bitwarden CVE published 2026-05-11

CVE-2026-43638

CVE-2026-43638 is a missing authorization vulnerability in Bitwarden Server prior to v2026.4.1. An authenticated user can write ciphers into an arbitrary organization via `POST /ciphers/import-organization` by submitting an empty `collections` array, which causes the server-side permission check to be skipped. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The vulnerability was patch [truncated]