CVE-2023-27706: Bitwarden
High severity, CVSS 7.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Bitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, accessible to other local unprivileged processes.
Affected products
- Bitwarden Bitwarden: before 2023.4.0 (fixed in 2023.4.0)
Published 2023-06-09. Last modified 2026-06-17.