Skip to content
Bitwarden SSO Vulnerability CVE-2026-101878 Exposes User Accounts

Bitwarden SSO Vulnerability CVE-2026-101878 Exposes User Accounts

First seen 29 Sep 2026, 06:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 07:18 UTC
  • •CVE-2026-101878 allows unauthorized access via SSO due to identifier truncation.
  • •The vulnerability affects Bitwarden Server versions 2025.6.0 to 2026.5.0.
  • •Immediate patching is recommended to mitigate risks associated with this vulnerability.

A vulnerability in Bitwarden Server versions 2025.6.0 to 2026.5.0 allows attackers to exploit a mismatch in the SSO login process. The @ExternalId parameter in the User_ReadBySsoUserOrganizationIdExternalId stored procedure is declared as NVARCHAR(50), while the corresponding column can store NVARCHAR(300). This discrepancy leads to silent truncation of identifiers, enabling an attacker with a crafted identifier to authenticate as another user if their identifier begins with the victim's 50-character prefix. The vulnerability, tracked as CVE-2026-101878, has been rated high severity by the reporter, although Bitwarden classified it as medium. Affected systems include both cloud and self-hosted deployments using SQL Server. The issue was reported to HackerOne and has been patched in release v2026.5.0 on May 29, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-29
Patch released for Bitwarden
Bitwarden released version 2026.5.0 to address the SSO vulnerability CVE-2026-101878.
sanjokkarki.com.np
2026-09-29
CVE-2026-101878 published
Bitwarden disclosed a vulnerability allowing SSO identifier truncation, enabling unauthorized access.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-101878 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed