CyberRota Analysis
AI-GeneratedBitwarden Server versions prior to 2026.7.2 are vulnerable due to a lack of verification for the caller's organizational membership in POST /collect requests, enabling authenticated users to create forged and backdated entries in any organization's audit log. This could lead to unauthorized manipulation of audit records, potentially compromising the integrity of organizational security audits. Organizations using Bitwarden Server should prioritize this vulnerability to prevent misuse of their audit logs.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any authenticated user to write forged, arbitrarily backdated entries into any organization's audit log.