Bitwarden
8 known vulnerabilities
Top Products
Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to t
Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens()
Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to ac
Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users wi
Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an or
Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user t
Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to
Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code.
Frequently Asked Questions
How many CVEs affect Bitwarden?
Bitwarden has 8 CVE records in our database, including 1 critical and 4 high severity vulnerabilities.
What are the most severe Bitwarden vulnerabilities?
Bitwarden has 1 critical severity (CVSS 9.0+) and 4 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Bitwarden vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Bitwarden products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Bitwarden Vulnerabilities
CyberStrike scans your infrastructure for Bitwarden vulnerabilities and provides real-time remediation guidance.
Get Started