{"id":"CVE-2026-101878","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-101878","summary":"Bitwarden Server 2025.6.0 < 2025.6.0 Authentication Bypass via SSO Identifier Truncation","details":"Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login identifier on SQL Server deployments and allowing a user whose identity-provider identifier begins with another organization member's full 50-character identifier to authenticate as that member and obtain a victim-scoped access token.","published":"2026-09-29T01:58:32.484Z","modified":"2026-09-30T03:47:01.547403912Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/bitwarden/server/commit/27ae3d5455f723975fac03819eaeba8710666bc4","label":"bitwarden/server@27ae3d5"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101878.json"},{"type":"ADVISORY","url":"https://github.com/bitwarden/server/releases/tag/v2026.5.0"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101878"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/bitwarden-server-authentication-bypass-via-sso-identifier-truncation"},{"type":"REPORT","url":"https://github.com/bitwarden/server/pull/7501"},{"type":"FIX","url":"https://github.com/bitwarden/server/commit/27ae3d5455f723975fac03819eaeba8710666bc4"},{"type":"PACKAGE","url":"https://github.com/bitwarden/server"},{"type":"EVIDENCE","url":"https://sanjokkarki.com.np/blog/bitwarden-sso-externalid-truncation"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-30T03:47:01.547403912Z"}}