Sceawere
Vulnerability Detail
CVE-2026-101878UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Bitwarden SSO Identifier Truncation Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 5h ago
- Vendor
- bitwarden
- Product
- bitwarden server
- Attack Type
- Incorrect Implementation of Authentication Algorithm
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login identifier on SQL Server deployments and allowing a user whose identity-provider identifier begins with another organization member's full 50-character identifier to authenticate as that member and obtain a victim-scoped access token.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-29T02:16:54.990Z",
"pubdate": "2026-09-29T02:16:54.990Z",
"executiveSummary": "This vulnerability involves an improper data type declaration within the Bitwarden Server stored procedure User_ReadBySsoUserOrganizationIdExternalId, affecting versions 2025.6.0 through 2026.4.x on SQL Server deployments.\nThe flaw stems from a mismatch between the procedure parameter definition, which is constrained to NVARCHAR(50), and the underlying database schema column, which accommodates NVARCHAR(300).\nThis discrepancy leads to the silent truncation of SSO login identifiers. Consequently, an attacker possessing an Identity Provider (IdP) identifier that shares an initial 50-character prefix with a legitimate organization member can trigger an authentication collision.\nThe impact is critical, as it allows an unauthorized actor to successfully authenticate as the victim, gaining access to the victim's scoped vault data and associated organizational resources.\nSuccessful exploitation requires the attacker to have a valid IdP account within the same organizational environment, where their external ID can be crafted or manipulated to match the truncated prefix of a target user.",
"technicalDetails": "The root cause of this vulnerability is a type-mismatch error within the stored procedure 'User_ReadBySsoUserOrganizationIdExternalId'. In SQL Server environments, the '@ExternalId' input parameter is explicitly typed as NVARCHAR(50). However, the database schema defines the 'ExternalId' column as NVARCHAR(300).\nWhen an SSO authentication request is processed, the SQL Server engine implicitly truncates any input string longer than 50 characters to fit the parameter definition before executing the query. This silent truncation occurs without throwing an exception or warning.\nThe attack flow proceeds as follows: 1) An attacker identifies a target user's external ID within the organization's IdP directory. 2) The attacker leverages the truncation behavior by utilizing an external ID that begins with the exact first 50 characters of the victim's ID. 3) Upon initiating an SSO login, the Bitwarden server invokes 'User_ReadBySsoUserOrganizationIdExternalId' with the attacker's full ID. 4) The SQL engine truncates this ID to the first 50 characters, effectively transforming the attacker's identifier into an exact match for the victim's identifier within the context of the SQL query.\nBecause the query performs a lookup based on this truncated value, the application logic incorrectly identifies the attacker as the victim. This results in the issuance of a valid authentication token scoped to the victim's account permissions.\nThis flaw effectively bypasses the integrity of the SSO handshake, as the application cannot distinguish between the attacker and the victim once the query result returns the victim's record. The vulnerability is limited to SQL Server deployments, as the discrepancy is specific to the stored procedure definitions for that database engine. Post-exploitation, the attacker assumes the identity of the target user, enabling unauthorized access to sensitive secrets, vault items, and organizational administrative functions defined by the victim's role, leading to a complete compromise of the victim's security context."
}