bitwarden是Bitwarden开源的一款密码管理后端服务。 bitwarden 2026.4.0之前版本存在安全漏洞,该漏洞源于缺少授权检查,允许提供商服务用户将任意组织添加到其提供商,导致目标组织被接管。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43640 | 8.1 HIGH | Bitwarden Server < 2026.4.1 Authentication Bypass via SCIM API Key |
| CVE-2026-43638 | 5.4 MEDIUM | Bitwarden Server < 2026.4.1 Missing Authorization via Organization Cipher Import |
No comments yet