PT-2026-39716 · Bitwarden · Server

Sanjok Karki

·

Published

2026-05-11

·

Updated

2026-05-11

·

CVE-2026-43639

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via POST /providers/{providerId}/clients/existing, resulting in takeover of the target organization; self-hosted installations are unaffected as this endpoint is restricted to Cloud via SelfHosted(NotSelfHostedOnly = true).

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-43639

Affected Products

Server