---
id: CVE-2026-101878
title: >-
  Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter
  of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as
  NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently
  truncating the SSO…
summary: >-
  Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter
  of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as
  NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently
  truncating the SSO…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-303
vendor: bitwarden
product: bitwarden server
affected:
  - server >= 2025.6.0 < 2026.5.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T02:16:54.990'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101878'
references:
  - url: >-
      https://github.com/bitwarden/server/commit/27ae3d5455f723975fac03819eaeba8710666bc4
    label: disclosure@vulncheck.com
  - url: 'https://github.com/bitwarden/server/pull/7501'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/bitwarden/server/releases/tag/v2026.5.0'
    label: disclosure@vulncheck.com
  - url: 'https://sanjokkarki.com.np/blog/bitwarden-sso-externalid-truncation'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/bitwarden-server-authentication-bypass-via-sso-identifier-truncation
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T02:25:39.971Z'
---

## Overview

Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login identifier on SQL Server deployments and allowing a user whose identity-provider identifier begins with another organization member's full 50-character identifier to authenticate as that member and obtain a victim-scoped access token.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
