« Volver al listado

Bitwarden

Bitwarden Server: vulnerabilidades y CVE

Bitwarden Server tiene 10 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses8
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-101878Alta (7.7)0.26%—29 sept 2026
Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently…
CVE-2026-60104Crítica (9.3)0.37%—8 jul 2026
Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's…
CVE-2026-57522Baja (2.3)0.46%—25 jun 2026
Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates without JSON encoding.…
CVE-2026-57521Media (5.3)0.43%—25 jun 2026
Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the…
CVE-2026-57520Alta (7.1)0.64%—25 jun 2026
Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing…
CVE-2026-43640Alta (8.6)0.71%—11 may 2026
Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain…
CVE-2026-43639Alta (8.9)0.84%—11 may 2026
Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST…
CVE-2026-43638Media (5.3)0.33%—11 may 2026
Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /ciphers/import-organization` by submitting…
CVE-2020-15879Alta (7.5)2.7%—21 jul 2020
Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16).
CVE-2019-19766Alta (7.5)1.3%—12 dic 2019
The Bitwarden server through 1.32.0 has a potentially unwanted KDF.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078.004 Cloud Accounts1
  2. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Bitwarden