High severity7.1NVD Advisory· Published Jun 9, 2023· Updated Jun 17, 2026
CVE-2023-27706
CVE-2023-27706
Description
Bitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, accessible to other local unprivileged processes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Bitwarden/Windows desktop applicationdescription
Patches
Vulnerability mechanics
References
3- hackerone.com/reports/1874155nvdExploitIssue TrackingThird Party Advisory
- github.com/bitwarden/clients/blob/8b5a223ad4ca0f89b6c9bcdbddef464d1755d2c0/apps/desktop/desktop_native/src/biometric/windows.rsnvdProduct
- github.com/bitwarden/clients/blob/8b5a223ad4ca0f89b6c9bcdbddef464d1755d2c0/apps/desktop/desktop_native/src/password/windows.rsnvdProduct
News mentions
0No linked articles in our index yet.