CVE-2026-101878 | Bitwarden Server 1.35.1/2026.4.0/2026.4.1 SSO Login User_ReadBySsoUserOrganizationIdExternalId improper authentication

SecurityVulns

A vulnerability identified as critical has been detected in Bitwarden Server 1.35.1/2026.4.0/2026.4.1. The impacted element is the function User_ReadBySsoUserOrganizationIdExternalId of the component SSO Login. Performing a manipulation of the argument ExternalId results in improper authentication.

This vulnerability is identified as CVE-2026-101878. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More