All AES-CBC data is authenticated with HMAC SHA-256. This was highlighted in the BWN-01-011 issue (which was determined to be a false positive since it was deemed that authentication was properly done).
Recommendation: If there is no HMAC tag with a ciphertext, immediately throw an exception. It makes it clearer that a decryption failure occurred (thus avoiding false positives).
[1]: https://github.com/bitwarden/jslib/blob/master/src/services/...
The AES-CBC thing is tied to the key, right? So the downgrade attack isn't possible.