CVE-2026-60104

Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication request, bound to an attacker-controlled public key, that is readable from an unauthenticated endpoint once approved resulting in disclosure of the victim's vault key and account takeover.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bitwarden:server:*:*:*:*:*:*:*:*

History

20 Jul 2026, 14:34

Type Values Removed Values Added
CPE cpe:2.3:a:bitwarden:server:*:*:*:*:*:*:*:*
First Time Bitwarden server
Bitwarden
References () https://github.com/bitwarden/server/commit/dcf4c486b2b5bedecc03a48b427243328cc74a9a - () https://github.com/bitwarden/server/commit/dcf4c486b2b5bedecc03a48b427243328cc74a9a - Patch
References () https://github.com/bitwarden/server/pull/7615 - () https://github.com/bitwarden/server/pull/7615 - Issue Tracking, Patch
References () https://github.com/bitwarden/server/releases#release-v2026.6.0 - () https://github.com/bitwarden/server/releases#release-v2026.6.0 - Release Notes
References () https://sanjokkarki.com.np/blog/bitwarden-vault-key-heist - () https://sanjokkarki.com.np/blog/bitwarden-vault-key-heist - Exploit, Third Party Advisory
References () https://www.vulncheck.com/advisories/bitwarden-server-authorization-bypass-via-admin-auth-request - () https://www.vulncheck.com/advisories/bitwarden-server-authorization-bypass-via-admin-auth-request - Third Party Advisory

08 Jul 2026, 22:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : 8.7

08 Jul 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 20:17

Updated : 2026-07-20 14:34


NVD link : CVE-2026-60104

Mitre link : CVE-2026-60104

CVE.ORG link : CVE-2026-60104


JSON object : View

Products Affected

bitwarden

  • server
CWE
CWE-639

Authorization Bypass Through User-Controlled Key