CVE-2026-57520: Bitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpoint
Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in the bulk user-remove endpoint. Attackers can supply Admin organization-user IDs in a bulk DELETE request to bypass the guard enforced on the single-user removal path, effectively removing one or more Admin accounts from an organization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bitwarden Serverto a version that resolves this vulnerability.Fixed in 2026.5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57520?
The severity of CVE-2026-57520 is categorized as high with a score of 7.1.
How do I fix CVE-2026-57520?
To fix CVE-2026-57520, upgrade your Bitwarden Server to version 2026.5.0 or later.
What impact does CVE-2026-57520 have on Bitwarden users?
CVE-2026-57520 allows authenticated users with the ManageUsers permission to remove Admin accounts, leading to potential privilege escalation.
Who is affected by CVE-2026-57520?
CVE-2026-57520 affects Bitwarden Server installations prior to version 2026.5.0, specifically organizations with custom user roles.
When was CVE-2026-57520 published?
CVE-2026-57520 was published on June 25, 2026.