Skip to content
CVE Alert: CVE-2026-101878 – bitwarden

CVE Alert: CVE-2026-101878 – bitwarden

Redpacketsecurity •admin • September 29, 2026

Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login identifier on SQL Server deployments and allowing a user whose identity-provider identifier begins with another organization member’s full 50-character identifier to authenticate as that member and obtain a victim-scoped access token.

**Risk verdict:** Treat this as a high-impact risk wherever SSO and SQL Server are in use; KEV, SSVC and EPSS status were not provided, so active exploitation and urgency cannot be confirmed.

**Why this matters:** A successful attack could grant access to another user’s vault, exposing sensitive credentials and enabling follow-on access to business systems. The required identifier collision makes exploitation targeted rather than a likely mass, opportunistic attack.

**Most likely attack path:** An attacker needs network access and low-level privileges, plausibly an account or identity in the relevant SSO flow, plus a crafted identity-provider identifier matching the victim’s identifier prefix. No user interaction is required, but high attack complexity limits reliability; impact appears confined to the affected service’s security authority, with no indicated automatic lateral movement beyond credentials obtained.

**Who is most exposed:** Prioritise self-hosted password-manager deployments using SQL Server and SSO, especially organisations with long or externally managed identity identifiers.

Review SSO sign-ins for unexpected account-to-identity-provider identifier mismatches.

Alert on multiple accounts mapping to identifiers sharing a long prefix.

Correlate anomalous vault access or token issuance with newly created SSO identities.

Check authentication and SQL application logs for truncation-related lookup anomalies.

Mitigation and prioritisation:

Upgrade promptly to the vendor’s corrected release; validate SSO login and account mapping after deployment.

If immediate patching is not possible, temporarily restrict or disable affected SSO sign-in paths.

Review recent SSO sessions and revoke suspicious tokens; investigate affected vault access.

Confirm SQL Server use and obtain current KEV, SSVC and EPSS data to refine urgency.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

MITRE ATT&CK (1)

Platforms (1)