Bitwarden Server versions before 2026.6.0 contain an authorization bypass in POST /auth-requests/admin-request tracked as CVE-2026-60104. The flaw stems from the server failing to verify that the email address supplied in the request body belongs to the authenticated caller, allowing a low-privileged organization member to initiate a Trusted Device Encryption authentication request on behalf of another user.
If the victim approves the request, an attacker can bind it to an attacker-controlled public key and then use an unauthenticated endpoint to obtain the victim's vault key and a victim-scoped access token, resulting in full account takeover. The issue is classified as CWE-639 and carries a CVSS v3.1 score vector of AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N; Bitwarden addressed the vulnerability in version 2026.6.0.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-60104 was publicly listed as an authorization bypass affecting Bitwarden Server versions before 2026.6.0. The listing states the flaw stems from failure to verify that the email address in an admin auth request belongs to the authenticated caller and references the fixing release and related technical materials.
VulnCheck published an advisory describing an authorization flaw in Bitwarden Server before version 2026.6.0. The write-up says a low-privileged organization member could abuse POST /auth-requests/admin-request to obtain a victim's vault key and victim-scoped access token, leading to account takeover.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.