Bitwarden Server Missing Authorization Vulnerability in Provider Clients Endpoint Allowing Organization Takeover

Vulnerability

A missing authorization vulnerability has been identified in Bitwarden Server versions prior to 2026.4.0. This vulnerability allows a provider service user to add an arbitrary organization to their provider through the POST /providers/{providerId}/clients/existing endpoint. As a result, the attacker can take over the target organization. Self-hosted installations are not affected, as this endpoint is restricted to Cloud users.

Impact

Exploitation of this vulnerability allows for unauthorized takeover of organizations by linking them to the attacker's provider account. This includes canceling the organization's Stripe subscription, rewriting billing information, and managing the organization's status.

Reproduction

To reproduce this vulnerability, a provider service user must send a POST request to the /providers/{providerId}/clients/existing endpoint with a valid provider ID and an organization ID that belongs to a different user. The request must include a key, which can be arbitrary. If the organization ID is accepted, the takeover is successful.

Remediation

Users can update to Bitwarden Server version 2026.4.0 or later, where this vulnerability has been fixed.

Added: May 11, 2026, 6:31 PM
Updated: May 11, 2026, 6:31 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
6.2
remediation
7.7
relevance
8.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.