📦

server

Vendor: bitwarden

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 6 Total Indexed
Avg. EPSS 0.20% Exploit Prob.
Latest CVE CVE-2026-43640 May 11

Security Vulnerability Index

Page 1 / 1
8.6 CVSS

Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain the key using only a valid session.

EPSS: 0.13%
8.9 CVSS

Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{providerId}/clients/existing`, resulting in takeover of the target organization; self-hosted installations are unaffected as this endpoint is restricted to Cloud via SelfHosted(NotSelfHostedOnly = true).

EPSS: 0.04%
5.3 CVSS

Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /ciphers/import-organization` by submitting an empty `collections` array, which causes the server-side permission check to be skipped.

EPSS: 0.03%
7.5 CVSS

Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16).

EPSS: 0.51%
7.5 CVSS

The Bitwarden server through 1.32.0 has a potentially unwanted KDF.

EPSS: 0.27%