📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Patch & vulnerability status

Bitwarden Server Bitwarden Inc.

Bitwarden Server

Release status, tracked CVEs, and automated cross-platform patching for Bitwarden Server.

PlatformLatest versionCVEs trackedLast checked
Windows92024-05-27

Known vulnerabilities (CVEs) in Bitwarden Server

Lavawall tracks 9 published CVEs affecting Bitwarden Server, and deploys the versions that fix them automatically across your fleet.

CVEPublishedSeverityDetailsVector
CVE-2026-601042026-07-08 20:17:00CRITICAL (9)Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication request, bound to an attacker-controlled public key, that is readable from an unauthenticated endpoint once approved resulting in disclosure of the victim's vault key and account takeover.NETWORK
CVE-2026-575222026-06-25 20:17:17LOW (2)Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates without JSON encoding. When an organization has configured an event integration whose template references a user-controlled token (such as #ActingUserName# or #UserName#, populated from a member's display name), an authenticated member can set their display name to JSON metacharacters and inject arbitrary key-value pairs into the rendered payloads delivered to webhook, SIEM, Slack, Teams, or Datadog endpoints, making injected fields indistinguishable from legitimate template output.NETWORK
CVE-2026-575212026-06-25 20:17:17MEDIUM (5)Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the PreviewInvoiceController endpoints without membership or authorization checks. Attackers can exploit the missing ManageOrganizationBillingRequirement on the preview invoice endpoints to retrieve Stripe-computed tax totals, subscription status, and billing details derived from any target organization's real customer and subscription data.NETWORK
CVE-2026-575202026-06-25 20:17:17HIGH (7)Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in the bulk user-remove endpoint. Attackers can supply Admin organization-user IDs in a bulk DELETE request to bypass the guard enforced on the single-user removal path, effectively removing one or more Admin accounts from an organization.NETWORK
CVE-2026-436402026-05-11 18:16:37HIGH (9)Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain the key using only a valid session.NETWORK
CVE-2026-436392026-05-11 18:16:37HIGH (9)Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{providerId}/clients/existing`, resulting in takeover of the target organization; self-hosted installations are unaffected as this endpoint is restricted to Cloud via SelfHosted(NotSelfHostedOnly = true).NETWORK
CVE-2026-436382026-05-11 18:16:37MEDIUM (5)Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /ciphers/import-organization` by submitting an empty `collections` array, which causes the server-side permission check to be skipped.NETWORK
CVE-2020-158792020-07-21 17:15:12HIGH (8)Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16).NETWORK
CVE-2019-197662019-12-12 19:15:21HIGH (8)The Bitwarden server through 1.32.0 has a potentially unwanted KDF.NETWORK

Why keeping Bitwarden Server patched matters

Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Bitwarden Server release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.

How Lavawall® patches Bitwarden Server

Lavawall® watches Bitwarden Server releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Bitwarden Server, one policy to bring them current, and timestamped evidence for audits.

Frequently asked questions

What is the latest version of Bitwarden Server?
Lavawall tracks Bitwarden Server (last checked 2024-05-27). New releases are monitored continuously and can be deployed automatically across your fleet.
Does Bitwarden Server have known security vulnerabilities (CVEs)?
Lavawall tracks 9 CVEs for Bitwarden Server and remediates them automatically as part of patching.
How do I patch Bitwarden Server automatically?
Deploy the Lavawall® agent and Bitwarden Server updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.

Lavawall® monitors releases and CVEs for Bitwarden Server through public information and proprietary statistical analysis, and can patch it automatically across your fleet.