bitwarden是Bitwarden开源的一款密码管理后端服务。 Bitwarden 2026.4.1之前版本存在安全漏洞,该漏洞源于缺少授权检查,允许任何经过身份验证的用户通过提交空collections数组向任意组织写入密码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43640 | 8.1 HIGH | Bitwarden Server < 2026.4.1 Authentication Bypass via SCIM API Key |
| CVE-2026-43639 | 8.0 HIGH | Bitwarden Server < 2026.4.0 Missing Authorization via Provider Clients |
No comments yet