Bitwarden
Bitwarden Server: vulnerabilidades y CVE
Bitwarden Server tiene 10 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses8
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-101878 | Alta (7.7) | 0.26% | — | 29 sept 2026 | Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently… |
| CVE-2026-60104 | Crítica (9.3) | 0.37% | — | 8 jul 2026 | Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's… |
| CVE-2026-57522 | Baja (2.3) | 0.46% | — | 25 jun 2026 | Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates without JSON encoding.… |
| CVE-2026-57521 | Media (5.3) | 0.43% | — | 25 jun 2026 | Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the… |
| CVE-2026-57520 | Alta (7.1) | 0.64% | — | 25 jun 2026 | Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing… |
| CVE-2026-43640 | Alta (8.6) | 0.71% | — | 11 may 2026 | Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain… |
| CVE-2026-43639 | Alta (8.9) | 0.84% | — | 11 may 2026 | Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST… |
| CVE-2026-43638 | Media (5.3) | 0.33% | — | 11 may 2026 | Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /ciphers/import-organization` by submitting… |
| CVE-2020-15879 | Alta (7.5) | 2.7% | — | 21 jul 2020 | Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16). |
| CVE-2019-19766 | Alta (7.5) | 1.3% | — | 12 dic 2019 | The Bitwarden server through 1.32.0 has a potentially unwanted KDF. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.