{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/bitwarden-server--2026.5.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:bitwarden:server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-101878"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Bitwarden Server (\u003c 2026.5.0)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","cve-2026-101878","identity-management"],"_cs_type":"advisory","_cs_vendors":["Bitwarden"],"content_html":"\u003cp\u003eBitwarden Server versions 2025.6.0 through versions prior to 2026.5.0 contain a critical authentication vulnerability involving the 'User_ReadBySsoUserOrganizationIdExternalId' stored procedure. When deployed on Microsoft SQL Server, the application declares the '@ExternalId' input parameter with a length of NVARCHAR(50), while the underlying database column is defined as NVARCHAR(300). This discrepancy results in silent truncation of SSO login identifiers. An attacker with a malicious SSO identifier that shares the same first 50 characters as a legitimate user's identifier can successfully authenticate as that victim. This allows the attacker to obtain a victim-scoped access token, leading to unauthorized access to the victim's vault and organizational data. This vulnerability poses a significant risk to organizations relying on SSO for centralized identity management.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in unauthorized account takeover within a Bitwarden organization. Attackers can gain access to sensitive credentials, secure notes, and other vault items associated with the victim's account. This impacts the confidentiality and integrity of all organizations using the affected Bitwarden Server versions on SQL Server backends, potentially leading to widespread data breaches or administrative account compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all internet-facing or organization-critical Bitwarden Server instances to version 2026.5.0 or later. Monitor SQL Server logs for unexpected authentication events or high volumes of SSO login attempts associated with unusually long or truncated external identifiers.\u003c/p\u003e\n","date_modified":"2026-09-29T02:24:14Z","date_published":"2026-09-29T02:24:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-bitwarden-sso-truncation/","summary":"A SQL Server stored procedure parameter truncation vulnerability (CVE-2026-101878) in Bitwarden Server allows attackers to authenticate as other users by crafting overlapping SSO identifiers.","title":"Authentication Bypass in Bitwarden Server via SSO Identifier Truncation","url":"https://feed.craftedsignal.io/briefs/2026-09-bitwarden-sso-truncation/"}],"language":"en","title":"CraftedSignal Threat Feed - Bitwarden Server (\u003c 2026.5.0)","version":"https://jsonfeed.org/version/1.1"}