CVE-2026-57520
HIGHBitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpoint
Title source: cnaDescription
Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in the bulk user-remove endpoint. Attackers can supply Admin organization-user IDs in a bulk DELETE request to bypass the guard enforced on the single-user removal path, effectively removing one or more Admin accounts from an organization.
References (5)
Core 5
Core References
Exploit technical-description
exploit
https://sanjokkarki.com.np/blog/bitwarden-bulk-remove-admin
Release Notes release-notes
https://github.com/bitwarden/server/releases/tag/v2026.5.0
Issue Tracking issue-tracking
https://github.com/bitwarden/server/pull/7526
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/bitwarden-server-privilege-escalation-via-bulk-user-remove-endpoint
Scores
CVSS v3
7.1
EPSS
0.0035
EPSS Percentile
27.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (1)
bitwarden/server
< 2026.5.0 (2 CPE variants)
Published
Jun 25, 2026
Tracked Since
Jun 26, 2026