Broken Access Control in Bitwarden Server Affecting User Billing Data
CVE-2026-57521
Key Information:
Badges
What is CVE-2026-57521?
Bitwarden Server versions prior to 2026.5.0 exhibit a broken access control vulnerability that permits authenticated users to retrieve unauthorized organization billing data. By exploiting the PreviewInvoiceController endpoints, attackers can submit arbitrary organization IDs without proper membership or authorization, gaining access to sensitive details such as Stripe-calculated tax totals, subscription statuses, and billing information of targeted organizations. This vulnerabilities arise from the lack of crucial access management checks in the preview invoice processes, potentially exposing real customer data.
Affected Version(s)
server 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
