LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-43640

CVE-2026-43640 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: May 11, 2026

Bitwarden Server - Authentication Bypass

Published: May 11, 2026Updated: May 11, 2026Remote Exploitable

Overview

Bitwarden Server < v2026.4.1 contains a broken authentication caused by lack of master-password re-authentication when retrieving or rotating an organization's SCIM API key, letting authenticated users with SCIM management privileges obtain the key using only a valid session.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 5.5%(Probability of exploitation in next 30 days)

Impact

Authenticated users with SCIM management privileges can obtain the organization's SCIM API key, risking unauthorized access and potential data compromise.

Mitigation

Update to version v2026.4.1 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
May 11, 2026

🟠 CVE-2026-43640 - High (8.1) Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain the key using only a valid ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-43640/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
May 11, 2026

🟠 CVE-2026-43640 - High (8.1) Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain the key using only a valid ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-43640/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-43640
Severity
High
CVSS Score
8.1
Type
broken_authentication
Status
new
EPSS
5.5%
Social Posts
2

CWE

  • CWE-303

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS Score

5.5%Probability of exploitation in the next 30 days