What bitwarden/server shipped
Written by FoxPlug from public releases; not affiliated with Bitwarden. An automatic summary of the public release, pull request and commit data of github.com/bitwarden/server. Bitwarden did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Fixed API base URL scheme for Slack and Teams integration to use HTTPS instead of HTTP. Pull request #8449
- Added required TenantId setting for Teams integration to comply with Microsoft requirements. Pull request #8452
- Added GET /account/billing/subscription/preview endpoint for individual subscription page preview cart. Pull request #8435
- Added SCIM 2.0 discovery endpoints (ServiceProviderConfig, Schemas, ResourceTypes) for RFC 7643/7644 compliance. Pull request #8430
- Added PamSeats and MaxAutoscalePamSeats columns to Organization table for PAM billing support. Pull request #8405
- Fixed EF Core CollectionCipherRepository.UpdateCollectionsAsync() to scope collection removal to caller's available collections. Pull request #8441
- Fixed collection access validation to reject invalid permission combinations of Manage with ReadOnly or HidePasswords for users. Pull request #8413
- Made dead letter sweep interval configurable via AzureServiceBus.DeadLetterCleanupInterval setting. Pull request #8401
- Added email verification check to confirm-invite endpoint. Pull request #8418
- Upgraded mjml and mjml-core from 4.15.3 to 5.4.1 with security fixes. Pull request #8388
Why it matters
This week includes security fixes for collection access validation and Teams/Slack integrations, new SCIM 2.0 discovery endpoints for enterprise compliance, and billing infrastructure improvements for PAM and subscription preview features. Configuration flexibility was added for dead letter queue cleanup and email template tooling was modernized.
Changelog entry
- Fixed API base URL scheme for Slack and Teams integration Pull request #8449
- Added TenantId setting for Teams integration Pull request #8452
- Added GET /account/billing/subscription/preview endpoint Pull request #8435
- Added SCIM 2.0 discovery endpoints Pull request #8430
- Added PamSeats and MaxAutoscalePamSeats columns to Organization Pull request #8405
- Fixed EF Core collection removal scoping to caller's collections Pull request #8441
- Fixed collection access validation for invalid permission combinations Pull request #8413
- Made dead letter sweep interval configurable Pull request #8401
- Added email verification check to confirm-invite endpoint Pull request #8418
- Upgraded mjml to 5.4.1 with security fixes Pull request #8388
This week: SCIM 2.0 discovery endpoints for Microsoft Entra eligibility, fixed collection access validation, Teams integration TenantId support, and security updates for billing and SSO error handling.
New in Bitwarden server: SCIM 2.0 discovery endpoints (ServiceProviderConfig, Schemas, ResourceTypes) now available for RFC 7643/7644 compliance and Microsoft Entra App Gallery eligibility. Also shipped: fixed collection access validation to prevent invalid permission combinations, Teams integration TenantId requirement, configurable dead letter queue cleanup intervals, and security improvements for billing and SSO error disclosure.
Week of September 14, 2026
What shipped
- Version 2026.9.0 released with organization delete tasks, event integration dead letter retention, and Fido2 v4 upgrades. Release
- Dead letter retention added for event integrations to prevent unbounded queue growth. Pull request #8364
- Secrets versioning implemented with feature flag gating and event logging for restore operations. Pull request #8307
- Fido2 v4 migration completed with Base64UrlSchemaFilter extended across all required properties. Pull request #8071
- Invited member collection and group access scoped to organization to prevent cross-organization access. Pull request #8347
- Encrypted string validation enhanced to check byte lengths of IV and MAC pieces at API boundary. Pull request #8328
- Email notifications added for collection approvers when access requests require decisions. Pull request #8290
- Email notifications added for requesters when their access requests are approved or denied. Pull request #8291
- Email notifications added for lease holders when operators revoke their access. Pull request #8292
- File ID validation added to reject manipulated file ID values from clients. Pull request #8326
Why it matters
Version 2026.9.0 ships critical infrastructure improvements for event handling and security validation, along with the completed Fido2 v4 migration and secrets versioning feature. Access control scoping fixes close authorization gaps, and a new PAM email notification system enables stakeholders to stay informed about access request decisions.
Changelog entry
- Version 2026.9.0 Release
- Secrets versioning with event logging and feature flag gating Pull request #8307
- Dead letter retention for event integrations Pull request #8364
- Fido2 v4 migration with Base64UrlSchemaFilter extended to all required properties Pull request #8071
- Invited member collection and group access scoped to organization Pull request #8347
- Encrypted string validation for IV and MAC piece byte lengths Pull request #8328
- File ID validation to reject manipulated values Pull request #8326
- Collection group and member access scoped to organization Pull request #8329
- PAM access notification mailer infrastructure Pull request #8289
- Email notifications for collection approvers on pending access requests Pull request #8290
- Email notifications for requesters on access request decisions Pull request #8291
- Email notifications for lease holders on access revocation Pull request #8292
- Deprecated Admin Console API endpoints removed Pull request #8342
- Service Bus application-cache broadcast removed in favor of ExtendedCache Pull request #8349
- Global lease duration ceiling raised to one year with enforcement Pull request #8378
- Send invite response type declared in OpenAPI spec Pull request #8283
- Send invite ability for staged users with configurable options Pull request #8281
Bitwarden Server 2026.9.0 is live. Secrets versioning, Fido2 v4, dead letter retention for event integrations, access control scoping fixes, and PAM email notifications.
Bitwarden Server 2026.9.0 is now available. This release includes secrets versioning with feature flag gating, completed Fido2 v4 migration, dead letter retention for event integrations to prevent queue growth, access control scoping fixes for invited members and collections, enhanced encrypted string validation, and a new PAM email notification system for access request decisions.