Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101878— Bitwarden Server 2025.6.0 < 2025.6.0 Authentication Bypass via SSO Identifier Truncation

Quick assessment

Affected
bitwarden bitwarden server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Bitwarden 服务器 2025.6.0 至 2026.5.0(不含 2026.5.0)版本中, 存储过程将 参数声明为 ,而其所查询的数据库列实际存储类型为 。这一不匹配导致在 SQL Server 部署环境下,SSO(单点登录)身份标识会被静默截断为前 50 个字符。攻击者可利用此缺陷,通过构造其身份提供者的标识符以另一位组织成员的完整 50 字符标识符作为前缀,从而冒充该成员进行认证,并获取仅限受害者范围访问的令牌。

CVSS 7.5 · High EPSS 0.26% · P16

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts

Affected Version Matrix 1

VendorProduct Version RangeStatus
bitwarden bitwarden server 2025.6.0< 2026.5.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101878

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bitwarden Server 2025.6.0 < 2025.6.0 Authentication Bypass via SSO Identifier Truncation
Source: CVE Program / CVE List V5
Vulnerability Description
Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login identifier on SQL Server deployments and allowing a user whose identity-provider identifier begins with another organization member's full 50-character identifier to authenticate as that member and obtain a victim-scoped access token.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
认证算法的不正确实现
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
bitwarden bitwarden server 2025.6.0 ~ 2026.5.0 -

II. Public POCs for CVE-2026-101878

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101878

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-101878 (2)

Security Blog Posts for CVE-2026-101878 (1)

Vendor Pages for CVE-2026-101878 (1)

Other References for CVE-2026-101878 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-101878

No comments yet


Leave a comment