CVE-2026-43640

HIGH

Bitwarden Server < 2026.4.1 Authentication Bypass via SCIM API Key

Title source: cna
STIX 2.1

Description

Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain the key using only a valid session.

Scores

CVSS v3 8.1
EPSS 0.0050
EPSS Percentile 38.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-303
Status published
Products (1)
bitwarden/server < 2026.4.1 (2 CPE variants)
Published May 11, 2026
Tracked Since May 11, 2026