<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Bitwarden Server (&lt; 2026.5.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/bitwarden-server--2026.5.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 02:24:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/bitwarden-server--2026.5.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in Bitwarden Server via SSO Identifier Truncation</title><link>https://feed.craftedsignal.io/briefs/2026-09-bitwarden-sso-truncation/</link><pubDate>Tue, 29 Sep 2026 02:24:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-bitwarden-sso-truncation/</guid><description>A SQL Server stored procedure parameter truncation vulnerability (CVE-2026-101878) in Bitwarden Server allows attackers to authenticate as other users by crafting overlapping SSO identifiers.</description><content:encoded><![CDATA[<p>Bitwarden Server versions 2025.6.0 through versions prior to 2026.5.0 contain a critical authentication vulnerability involving the 'User_ReadBySsoUserOrganizationIdExternalId' stored procedure. When deployed on Microsoft SQL Server, the application declares the '@ExternalId' input parameter with a length of NVARCHAR(50), while the underlying database column is defined as NVARCHAR(300). This discrepancy results in silent truncation of SSO login identifiers. An attacker with a malicious SSO identifier that shares the same first 50 characters as a legitimate user's identifier can successfully authenticate as that victim. This allows the attacker to obtain a victim-scoped access token, leading to unauthorized access to the victim's vault and organizational data. This vulnerability poses a significant risk to organizations relying on SSO for centralized identity management.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in unauthorized account takeover within a Bitwarden organization. Attackers can gain access to sensitive credentials, secure notes, and other vault items associated with the victim's account. This impacts the confidentiality and integrity of all organizations using the affected Bitwarden Server versions on SQL Server backends, potentially leading to widespread data breaches or administrative account compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching all internet-facing or organization-critical Bitwarden Server instances to version 2026.5.0 or later. Monitor SQL Server logs for unexpected authentication events or high volumes of SSO login attempts associated with unusually long or truncated external identifiers.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authentication-bypass</category><category>cve-2026-101878</category><category>identity-management</category></item></channel></rss>