AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T14:17:26.870Z and has not been modified since then. This vulnerability affects Bitwarden Server deployments, allowing authenticated users to forge audit log entries. Defenders should assess exposure and prioritize verification and potential upgrades. The CVE record and NVD entry provide details o [truncated]
CVE-2026-60104 is a critical vulnerability in Bitwarden Server before version 2026.6.0. The issue allows a low-privileged organization member to obtain another user's vault key and a victim-scoped access token. This is achieved by creating a Trusted Device Encryption authentication request bound to an attacker-controlled public key. The request is readable from an unauthenticated endpoint once approved, r [truncated]
CVE-2026-43640 is a high-severity vulnerability in Bitwarden Server prior to v2026.4.1, allowing an authenticated user with SCIM management privileges to obtain the organization's SCIM API key without requiring master-password re-authentication. This vulnerability has significant implications for Bitwarden Server administrators and users with SCIM management privileges, as it could lead to unauthorized ac [truncated]
CVE-2026-43639 debrief: Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{providerId}/clients/existing`, resulting in takeover of the target organization. The vulnerability has a CVSS score of 8.9 and is classified as HIGH severity. Self-hosted installations are unaffected.
CVE-2026-43638 is a missing authorization vulnerability in Bitwarden Server prior to v2026.4.1. An authenticated user can write ciphers into an arbitrary organization via `POST /ciphers/import-organization` by submitting an empty `collections` array, which causes the server-side permission check to be skipped. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The vulnerability was patch [truncated]