OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-101878

HIGH · CVSS 7.5 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Bitwarden Server versions prior to 2026.5.0 are vulnerable due to a mismatch in the length of the @ExternalId parameter in the User_ReadBySsoUserOrganizationIdExternalId stored procedure, which can lead to SQL Server silently truncating SSO login identifiers. This flaw allows attackers to authenticate as other users by exploiting the truncated identifiers, potentially gaining unauthorized access to sensitive data. Organizations using affected Bitwarden Server versions should prioritize patching to mitigate the risk of credential misuse and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-101878
Severity
HIGH
CVSS
7.5
EPSS
0.26%

Original NVD Description

Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login identifier on SQL Server deployments and allowing a user whose identity-provider identifier begins with another organization member's full 50-character identifier to authenticate as that member and obtain a victim-scoped access token.