Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any authenticated user to write forged, arbitrarily backdated entries into any organization's audit log.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 14:17
Updated : 2026-08-17 19:16
NVD link : CVE-2026-71959
Mitre link : CVE-2026-71959
CVE.ORG link : CVE-2026-71959
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
