CVE-2026-57520

Published
View on NVD ↗
CVSS v3
7.1
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in the bulk user-remove endpoint. Attackers can supply Admin organization-user IDs in a bulk DELETE request to bypass the guard enforced on the single-user removal path, effectively removing one or more Admin accounts from an organization.

Bitwarden infrastructure/backend (API, database, Docker, etc).
GitHubGitHub
19.3K