Unrated severityNVD Advisory· Published Jul 8, 2026· Updated Jul 14, 2026
Bitwarden Server < 2026.6.0 Authorization Bypass via Admin Auth Request
CVE-2026-60104
Description
Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication request, bound to an attacker-controlled public key, that is readable from an unauthenticated endpoint once approved resulting in disclosure of the victim's vault key and account takeover.
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/bitwarden/server/commit/dcf4c486b2b5bedecc03a48b427243328cc74a9amitrepatch
- sanjokkarki.com.np/blog/bitwarden-vault-key-heistmitretechnical-descriptionexploit
- www.vulncheck.com/advisories/bitwarden-server-authorization-bypass-via-admin-auth-requestmitrethird-party-advisory
- github.com/bitwarden/server/pull/7615mitreissue-tracking
News mentions
0No linked articles in our index yet.