CVE-2026-43638 | bitwarden server up to 2026.4.0 import-organization authorization
A vulnerability was found in bitwarden server up to 2026.4.0. It has been rated as critical. Affected is an unknown function of the file /ciphers/import-organization. Performing a manipulation results in missing authorization.
This vulnerability is identified as CVE-2026-43638. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.