Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5g65-rmxf-rgj6

Опубликовано: 08 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.3

Описание

Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication request, bound to an attacker-controlled public key, that is readable from an unauthenticated endpoint once approved resulting in disclosure of the victim's vault key and account takeover.

Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication request, bound to an attacker-controlled public key, that is readable from an unauthenticated endpoint once approved resulting in disclosure of the victim's vault key and account takeover.

EPSS

Процентиль: 13%
0.00225
Низкий

8.5 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.7
nvd
29 дней назад

Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication request, bound to an attacker-controlled public key, that is readable from an unauthenticated endpoint once approved resulting in disclosure of the victim's vault key and account takeover.

CVSS3: 8.7
debian
29 дней назад

Bitwarden Server before 2026.6.0 does not verify that the email in a P ...

EPSS

Процентиль: 13%
0.00225
Низкий

8.5 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-639