Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-60104

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 8.7
CVSS3: 8
EPSS Низкий

Описание

Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication request, bound to an attacker-controlled public key, that is readable from an unauthenticated endpoint once approved resulting in disclosure of the victim's vault key and account takeover.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bitwarden:server:*:*:*:*:*:*:*:*
Версия до 2026.6.0 (исключая)

EPSS

Процентиль: 13%
0.00225
Низкий

8.7 High

CVSS3

8 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.7
debian
29 дней назад

Bitwarden Server before 2026.6.0 does not verify that the email in a P ...

CVSS3: 7.3
github
29 дней назад

Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication request, bound to an attacker-controlled public key, that is readable from an unauthenticated endpoint once approved resulting in disclosure of the victim's vault key and account takeover.

EPSS

Процентиль: 13%
0.00225
Низкий

8.7 High

CVSS3

8 High

CVSS3

Дефекты

CWE-639