Bitwarden Server
cpe:2.3:a:bitwarden:server:*:*:*:*:*:*:*
- < 2026.4.1
A vulnerability exists in Bitwarden Server versions prior to 2026.4.1, where the application does not require re-authentication of the master password when retrieving or rotating an organization's SCIM API key. This flaw allows an authenticated user with SCIM management privileges to access the key using only a valid session. The issue arises because the SCIM key type bypasses the necessary password verification, creating a security risk by enabling unauthorized access to sensitive API functionalities.
Exploitation of this vulnerability allows for unauthorized retrieval and rotation of SCIM API keys, which can be misused to manage users and groups within an organization, bypassing normal authentication requirements.
To reproduce this vulnerability, an authenticated user with SCIM management privileges can send a request to the SCIM API key retrieval endpoint without providing a valid master password. The absence of password verification for SCIM key requests will result in the API key being returned, demonstrating the authentication bypass.
Users can update to Bitwarden Server version 2026.4.1 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.