CVE-2026-60104
HIGHBitwarden Server < 2026.6.0 Authorization Bypass via Admin Auth Request
Title source: cnaDescription
Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication request, bound to an attacker-controlled public key, that is readable from an unauthenticated endpoint once approved resulting in disclosure of the victim's vault key and account takeover.
References (5)
Core 5
Core References
Patch patch
Fix Commit
https://github.com/bitwarden/server/commit/dcf4c486b2b5bedecc03a48b427243328cc74a9a
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/bitwarden-server-authorization-bypass-via-admin-auth-request
Exploit technical-description
exploit
Researcher Disclosure
https://sanjokkarki.com.np/blog/bitwarden-vault-key-heist
Release Notes release-notes
Release Notes
https://github.com/bitwarden/server/releases#release-v2026.6.0
Scores
CVSS v3
8.7
EPSS
0.0022
EPSS Percentile
12.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-639
Status
published
Products (1)
bitwarden/server
< 2026.6.0 (2 CPE variants)
Published
Jul 08, 2026
Tracked Since
Jul 09, 2026