Patch & vulnerability status
Bitwarden Inc.
Bitwarden Server
Release status, tracked CVEs, and automated cross-platform patching for Bitwarden Server.
| Platform | Latest version | CVEs tracked | Last checked |
|---|---|---|---|
| Windows | 9 | 2024-05-27 |
Known vulnerabilities (CVEs) in Bitwarden Server
Lavawall tracks 9 published CVEs affecting Bitwarden Server, and deploys the versions that fix them automatically across your fleet.
| CVE | Published | Severity | Details | Vector |
|---|---|---|---|---|
| CVE-2026-60104 | 2026-07-08 20:17:00 | CRITICAL (9) | Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication request, bound to an attacker-controlled public key, that is readable from an unauthenticated endpoint once approved resulting in disclosure of the victim's vault key and account takeover. | NETWORK |
| CVE-2026-57522 | 2026-06-25 20:17:17 | LOW (2) | Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates without JSON encoding. When an organization has configured an event integration whose template references a user-controlled token (such as #ActingUserName# or #UserName#, populated from a member's display name), an authenticated member can set their display name to JSON metacharacters and inject arbitrary key-value pairs into the rendered payloads delivered to webhook, SIEM, Slack, Teams, or Datadog endpoints, making injected fields indistinguishable from legitimate template output. | NETWORK |
| CVE-2026-57521 | 2026-06-25 20:17:17 | MEDIUM (5) | Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the PreviewInvoiceController endpoints without membership or authorization checks. Attackers can exploit the missing ManageOrganizationBillingRequirement on the preview invoice endpoints to retrieve Stripe-computed tax totals, subscription status, and billing details derived from any target organization's real customer and subscription data. | NETWORK |
| CVE-2026-57520 | 2026-06-25 20:17:17 | HIGH (7) | Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in the bulk user-remove endpoint. Attackers can supply Admin organization-user IDs in a bulk DELETE request to bypass the guard enforced on the single-user removal path, effectively removing one or more Admin accounts from an organization. | NETWORK |
| CVE-2026-43640 | 2026-05-11 18:16:37 | HIGH (9) | Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain the key using only a valid session. | NETWORK |
| CVE-2026-43639 | 2026-05-11 18:16:37 | HIGH (9) | Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{providerId}/clients/existing`, resulting in takeover of the target organization; self-hosted installations are unaffected as this endpoint is restricted to Cloud via SelfHosted(NotSelfHostedOnly = true). | NETWORK |
| CVE-2026-43638 | 2026-05-11 18:16:37 | MEDIUM (5) | Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /ciphers/import-organization` by submitting an empty `collections` array, which causes the server-side permission check to be skipped. | NETWORK |
| CVE-2020-15879 | 2020-07-21 17:15:12 | HIGH (8) | Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16). | NETWORK |
| CVE-2019-19766 | 2019-12-12 19:15:21 | HIGH (8) | The Bitwarden server through 1.32.0 has a potentially unwanted KDF. | NETWORK |
Why keeping Bitwarden Server patched matters
Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Bitwarden Server release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.
How Lavawall® patches Bitwarden Server
Lavawall® watches Bitwarden Server releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Bitwarden Server, one policy to bring them current, and timestamped evidence for audits.
Frequently asked questions
Lavawall tracks Bitwarden Server (last checked 2024-05-27). New releases are monitored continuously and can be deployed automatically across your fleet.
Lavawall tracks 9 CVEs for Bitwarden Server and remediates them automatically as part of patching.
Deploy the Lavawall® agent and Bitwarden Server updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.
Lavawall® monitors releases and CVEs for Bitwarden Server through public information and proprietary statistical analysis, and can patch it automatically across your fleet.