← Back

Bitwarden

bitwarden

10 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Server
server
Bitwarden
bitwarden
Cli
cli

CVEs (10)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bitwarden
1Server
May 16, 2026
May 11, 2026
8.6 HIGH· v4
8.1 HIGH· v3
N/A· v2
Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain...Show more
Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain the key using only a valid session.Show less
1Bitwarden
1Server
May 16, 2026
May 11, 2026
8.9 HIGH· v4
9.1 CRITICAL· v3
N/A· v2
Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{providerId}/clients/existing...Show more
Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{providerId}/clients/existing`, resulting in takeover of the target organization; self-hosted installations are unaffected as this endpoint is restricted to Cloud via SelfHosted(NotSelfHostedOnly = true).Show less
1Bitwarden
1Server
May 16, 2026
May 11, 2026
5.3 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /ciphers/import-organization` by submitting...Show more
Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /ciphers/import-organization` by submitting an empty `collections` array, which causes the server-side permission check to be skipped.Show less
1Bitwarden
1Cli
May 4, 2026
May 1, 2026
8.8 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx supply chain incident.
1Bitwarden
1Bitwarden
Nov 21, 2024
Aug 15, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.
1Bitwarden
1Bitwarden
Jan 6, 2025
Jun 9, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Bitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, accessible to other local unprivileged processes.
1Bitwarden
1Bitwarden
Nov 21, 2024
Mar 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Bitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for an example.com hosting provider when customer-website.example.com is visited. NOTE: the vendor's posi...Show more
Bitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for an example.com hosting provider when customer-website.example.com is visited. NOTE: the vendor's position is that "Auto-fill on page load" is not enabled by default.Show less
1Bitwarden
1Bitwarden
Nov 21, 2024
Mar 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element. NOTE: the vendor's position is that there have been important legitimate cross-domain configurations (e.g., an apple.com IFRAME e...Show more
Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element. NOTE: the vendor's position is that there have been important legitimate cross-domain configurations (e.g., an apple.com IFRAME element on the icloud.com website) and that "Auto-fill on page load" is not enabled by default.Show less
1Bitwarden
1Server
Nov 21, 2024
Jul 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16).
1Bitwarden
1Server
Nov 21, 2024
Dec 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Bitwarden server through 1.32.0 has a potentially unwanted KDF.