CVE-2026-43640
Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an or
Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain the key using only a valid session.
HIGH · CVSS 8.1
EPSS 0.00134
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules5
YARA rules0