CVE-2026-101878
Received Received - Intake

Authentication Bypass in Bitwarden Server via SSO Identifier Truncation

Vulnerability report for CVE-2026-101878, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login identifier on SQL Server deployments and allowing a user whose identity-provider identifier begins with another organization member's full 50-character identifier to authenticate as that member and obtain a victim-scoped access token.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bitwarden server to 2026.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-303 The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Bitwarden Server versions 2025.6.0 to 2026.5.0. It involves an SSO authentication bypass due to a mismatch in string lengths. The stored procedure uses an NVARCHAR(50) parameter for the SSO identifier, but the database column stores NVARCHAR(300). This causes the identifier to be truncated, allowing an attacker whose SSO identifier starts with another user's 50-character identifier to authenticate as that user and gain access to their data.

Detection Guidance

To detect this vulnerability, check the Bitwarden Server version installed on your system. If it is between 2025.6.0 and 2025.5.0 (excluding 2026.5.0), it is vulnerable. Run the command: bitwarden-server --version or check the server logs for version details.

Impact Analysis

If you use Bitwarden Server in the affected versions, an attacker could impersonate you by exploiting the SSO identifier truncation. This could lead to unauthorized access to your vault, sensitive data exposure, or actions performed under your identity. The impact includes potential data breaches, loss of confidentiality, and compromised account integrity.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles and HIPAA's security requirements. It may result in non-compliance with regulations mandating strict access controls and data integrity, potentially leading to legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Immediately upgrade Bitwarden Server to version 2026.5.0 or later to address the SSO identifier truncation issue. Verify the upgrade by checking the server version and reviewing the updated SQL migrations for the User_ReadBySsoUserOrganizationIdExternalId stored procedure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101878. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart