VYPR
High severity8.7NVD Advisory· Published Jul 8, 2026· Updated Jul 20, 2026

CVE-2026-60104

CVE-2026-60104

Description

Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication request, bound to an attacker-controlled public key, that is readable from an unauthenticated endpoint once approved resulting in disclosure of the victim's vault key and account takeover.

Affected products

2
  • Bitwarden/Serverllm-fuzzy2 versions
    <2026.6.0+ 1 more
    • (no CPE)range: <2026.6.0
    • cpe:2.3:a:bitwarden:server:*:*:*:*:*:*:*:*range: <2026.6.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.