high · CVSS v3 7.5 · CVSS v4 7.7
CVE-2026-101878
Bitwarden Server versions prior to 2026.5.0 incorrectly truncate the @ExternalId parameter in a stored procedure, allowing an attacker to im
Overview
Bitwarden Server versions prior to 2026.5.0 incorrectly truncate the @ExternalId parameter in a stored procedure, allowing an attacker to impersonate another user and obtain a victim‑scoped access token. This flaw affects SQL Server deployments of the Bitwarden Server and can be exploited by users with SSO identifiers that begin with another member’s 50‑character ID. The vulnerability enables unauthorized access to sensitive vault data.
Description
Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login identifier on SQL Server deployments and allowing a user whose identity-provider identifier begins with another organization member's full 50-character identifier to authenticate as that member and obtain a victim-scoped access token.
Impact
Confidentiality and integrity of user vaults are compromised as attackers can gain access to another member’s data. The attack does not directly affect availability, but it can lead to data breaches and loss of trust in the service. Defenders should consider the risk of credential theft and potential downstream attacks on other systems.
Remediation
Upgrade Bitwarden Server to version 2026.5.0 or later, which corrects the @ExternalId truncation. As an interim measure, restrict SSO identifiers to a maximum length of 50 characters or enforce strict validation on the server side. Monitor authentication logs for anomalous SSO logins and apply least‑privilege access controls to vaults.
Risk context
The vulnerability is rated high severity with CVSS v3 score 7.5 and CVSS v4 score 7.7. No EPSS data is available, but the flaw poses a significant risk to organizations using Bitwarden Server on SQL Server. Prompt patching is recommended.
Affected products
- Bitwarden Server 2025.x
- Bitwarden Server 2026.x
Scores
- Severity
- high
- CVSS v2
- 7.1
- CVSS v3
- 7.5
- CVSS v4
- 7.7
- EPSS
- —