Description
Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user-s vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication request, bound to an attacker-controlled public key, that is readable from an unauthenticated endpoint once approved resulting in disclosure of the victim-s vault key and account takeover.
CVSS 8.7EPSS 0.22499999999999998%Risque 0.89
Voir la source- Publication
- 2026-07-08 20:17:00
- Versions concernées
- <2026.6.0
- Type
- Logiciel critique
- Dernière modification
- 2026-07-20 14:34:32
- Vecteur
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N