Executive brief
Bitwarden Server is a password management solution used by organizations to secure and manage credentials. A security flaw was identified where users with administrative privileges for SCIM (System for Cross-domain Identity Management) could retrieve or change the organization's API key without being prompted for their master password. This could allow an attacker with access to a valid administrative session to gain persistent access to identity management functions or disrupt user provisioning services.
Technical details
An authentication bypass vulnerability exists in Bitwarden Server's OrganizationsController due to an incorrect implementation of the re-authentication logic. Specifically, the endpoints for retrieving (POST /organizations/{id}/api-key) and rotating (POST /organizations/{id}/rotate-api-key) SCIM API keys contained a boolean short-circuit bypass. The code explicitly exempted the 'Scim' API key type from the `VerifySecretAsync` check, allowing any authenticated user with SCIM management permissions to perform these actions using only their active session token. This bypasses the standard security requirement of providing a master password hash for sensitive administrative operations. The issue is resolved in version 2026.4.1 by removing the conditional check that exempted SCIM keys from verification.
Affected products
- Bitwarden Bitwarden Server < 2026.4.1
Timeline
- 2026-04-08: patched: Fix committed to repository and merged into main branch.
- 2026-05-05: advisory: Release v2026.4.1 published.
- 2026-05-11: disclosed: CVE-2026-43640 published.
References
- https://github.com/bitwarden/server/commit/eb251d9bf80724c87b187661783b9354d1784083
- https://github.com/bitwarden/server/pull/7403
- https://github.com/bitwarden/server/releases/tag/v2026.4.1
- https://sanjokkarki.com.np/blog/bitwarden-scim-key-bypass
- https://www.vulncheck.com/advisories/bitwarden-server-authentication-bypass-via-scim-api-key