CVE-2026-60104
Bitwarden Server versions before 2026.6.0 allow a low‑privileged user to trick the system into giving them another user’s vault key and access token. By sending a specially crafted request, the attacker can read the victim’s key from an unauthenticated endpoint, leading to account takeover. The vulnerability is critical because it enables full data theft.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Bitwarden Server versions before 2026.6.0, used by organizations to store encrypted user data.
Real-world impact
An attacker could obtain a victim’s vault key and access token, decrypt the victim’s data, and take over their account.
Why this severity
The CVSS score of 9.3 reflects the high impact of the vulnerability: it allows attackers to gain access to highly confidential data (vault key) and take over accounts with minimal effort, and it can be exploited remotely with low effort.
What to do about it
- 01Upgrade Bitwarden Server to version 2026.6.0 or later.
NVD description indicates fix in 2026.6.0
Timeline
- Jul 8, 2026 · 26d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.
- Jul 20, 2026 · 14d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/bitwarden/server/commit/dcf…patch
- github.com/bitwarden/server/pull/7615issue trackingpatch
- github.com/bitwarden/server/releasesrelease notes
- sanjokkarki.com.np/blog/bitwarden-vault-key-he…exploitthird party advisory
- vulncheck.com/advisories/bitwarden-server…third party advisory