CVE-2026-60104 is an authorization bypass vulnerability in Bitwarden Server affecting versions prior to 2026.6.0. The flaw exists in the Trusted Device Encryption authentication request flow because the server does not verify that the email address supplied in the POST /auth-requests/admin-request request body belongs to the authenticated caller. As a result, a low-privileged organization member can submit an authentication request for another user's email address while binding the request to an attacker-controlled public key. If the request is approved by an organization administrator, the resulting request data becomes accessible through an unauthenticated endpoint, allowing retrieval of the victim's encrypted vault key and a victim-scoped access token. Because the attacker controls the corresponding private key, the disclosed vault key material can be decrypted and used to compromise the victim account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical authorization bypass vulnerability in Bitwarden Server that lets a low-privileged organization member abuse the /auth-requests/admin-request flow to obtain another user's vault key and victim-scoped access token, leading to complete account takeover.
An authorization bypass / improper access control vulnerability in Bitwarden Server before 2026.6.0 that can let a low-privileged organization member obtain another user's vault key and victim-scoped access token, leading to account takeover.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.