Medium severity5.8NVD Advisory· Published Aug 10, 2026
CVE-2026-71959
CVE-2026-71959
Description
Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any authenticated user to write forged, arbitrarily backdated entries into any organization's audit log.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/bitwarden/server/commit/2aa92a3c8675a28e305e8207ff16592227f96291nvd
- github.com/bitwarden/server/pull/7934nvd
- github.com/bitwarden/server/releases/tag/v2026.7.2nvd
- sanjokkarki.com.np/blog/bitwarden-audit-log-forgerynvd
- www.vulncheck.com/advisories/bitwarden-server-audit-log-injection-via-post-collectnvd
News mentions
0No linked articles in our index yet.