Missing Authorization Vulnerability in Bitwarden Server by Bitwarden
CVE-2026-43639
Key Information:
Badges
What is CVE-2026-43639?
A vulnerability in Bitwarden Server versions prior to v2026.4.0 allows a provider service user to exploit a missing authorization mechanism. This flaw enables the user to add an arbitrary organization to their provider through a specific API endpoint, effectively taking over the target organization. This vulnerability is particularly relevant to cloud-hosted instances, as self-hosted installations are safeguarded from this risk due to restrictions imposed on the affected endpoint.
Affected Version(s)
server 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
