CVE-2026-101878 | Bitwarden Server 1.35.1/2026.4.0/2026.4.1 SSO Login User_ReadBySsoUserOrganizationIdExternalId improper authentication
A vulnerability identified as critical has been detected in Bitwarden Server 1.35.1/2026.4.0/2026.4.1. The impacted element is the function User_ReadBySsoUserOrganizationIdExternalId of the component SSO Login. Performing a manipulation of the argument ExternalId results in improper authentication.
This vulnerability is identified as CVE-2026-101878. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More