Bitwarden server是美国Bitwarden公司开源的一款密码管理服务器软件。 Bitwarden Server 2026.5.0之前版本存在授权问题漏洞,该漏洞源于访问控制不当,可能导致任何通过身份验证的用户通过向PreviewInvoiceController端点提供任意organizationId来访问任意组织账单数据,而无需进行成员资格或授权检查。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57520 | 7.1 HIGH | Bitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpoint |
| CVE-2026-57522 | 3.5 LOW | Bitwarden Server < 2026.5.0 JSON Injection via Webhook Templates |
No comments yet