
CVE-2026-43638 Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization … https://www.cve.org/CVERecord?id=CVE-2026-43638
Post summary
Bitwarden Server before v2026.4.1 contains a missing authorization flaw that lets authenticated users write ciphers into any organization; the issue is fixed in v2026.4.1.
