CVE-2026-43640Disclosure(bitwarden / server)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain the key using only a valid session.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-303

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • server

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-11); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
server

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-11: 1Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 105-1105-1205-13
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-43640: Missing authentication in JetBrains TeamCity, 8.2 rating 🔥 Vulnerability in JetBrains TeamCity allows an authenticated user to expose server API to unauthorized access. 👉 https://nt.ls/7tWNf

    Post summary

    The entry announces CVE-2026-43640, a missing-authentication flaw in JetBrains TeamCity with an 8.2 rating, allowing an authenticated user to expose the server API to unauthorized parties; no PoC, exploit, or patch details are provided.

    05060805
    7.6K followersView on X
  • Mr. OS@ksg93rd
    Disclosure

    CVE-2026-43640: Missing authentication in JetBrains TeamCity, 8.2 rating 🔥 Vulnerability in JetBrains TeamCity allows an authenticated user to expose server API to unauthorized access. Search at http://Netlas.io: 👉 Link: https://nt.ls/7tWNf 👉 Dork: http.headers.set_cookie:TCSESSIONID OR http.title:"teamcity" OR http.unknown_headers.key:"teamcity_node_id" OR http.meta:"teamcity" Read more: https://www.jetbrains.com/privacy-security/issues-fixed/

    Post summary

    The post announces CVE‑2026‑43640, a missing authentication flaw in JetBrains TeamCity that lets authenticated users expose server APIs to unauthorized access, but does not provide PoC, exploit code, or patch information.

    00001238
    3.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43640 Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authent… https://www.cve.org/CVERecord?id=CVE-2026-43640

    Post summary

    Announcement of CVE‑2026‑43640 in Bitwarden Server noting that the SCIM API key can be retrieved or rotated without master‑password re‑authentication, providing technical details but no exploitation or patch information.

    0000082
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbitwardenserver---

Explore more