CVE-2026-43640: Bitwarden Server < 2026.4.1 Authentication Bypass via SCIM API Key
Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain the key using only a valid session.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bitwarden Serverto a version that resolves this vulnerability.Fixed in 2026.4.1 - Compensating control
Ensure only trusted administrators have SCIM management privileges/access in Bitwarden Server to limit who can retrieve or rotate the organization’s SCIM API key.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43640?
CVE-2026-43640 is classified as a high-severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2026-43640?
To fix CVE-2026-43640, upgrade Bitwarden Server to version 2026.4.1 or later.
What does CVE-2026-43640 affect?
CVE-2026-43640 affects Bitwarden Server versions prior to 2026.4.1.
What is the nature of the vulnerability in CVE-2026-43640?
CVE-2026-43640 allows an authenticated user with SCIM management privileges to bypass master-password re-authentication when accessing the SCIM API key.
Who is at risk due to CVE-2026-43640?
Organizations using versions of Bitwarden Server prior to 2026.4.1 with SCIM management capabilities are at risk due to CVE-2026-43640.