Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Bitwarden Server < 2026.4.0 Missing Authorization via Provider Clients
Vulnerability Description
Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{providerId}/clients/existing`, resulting in takeover of the target organization; self-hosted installations are unaffected as this endpoint is restricted to Cloud via SelfHosted(NotSelfHostedOnly = true).
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
授权机制缺失
Vulnerability Title
bitwarden 安全漏洞
Vulnerability Description
bitwarden是Bitwarden开源的一款密码管理后端服务。 bitwarden 2026.4.0之前版本存在安全漏洞,该漏洞源于缺少授权检查,允许提供商服务用户将任意组织添加到其提供商,导致目标组织被接管。
CVSS Information
N/A
Vulnerability Type
N/A