CVE-2026-71959
Gravedad CVSS v4.0:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
10/08/2026
Última modificación:
10/08/2026
Descripción
*** Pendiente de traducción *** Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any authenticated user to write forged, arbitrarily backdated entries into any organization's audit log.
Impacto
Puntuación base 4.0
6.90
Gravedad 4.0
MEDIA
Puntuación base 3.x
5.80
Gravedad 3.x
MEDIA
Referencias a soluciones, herramientas e información
- https://github.com/bitwarden/server/commit/2aa92a3c8675a28e305e8207ff16592227f96291
- https://github.com/bitwarden/server/pull/7934
- https://github.com/bitwarden/server/releases/tag/v2026.7.2
- https://sanjokkarki.com.np/blog/bitwarden-audit-log-forgery
- https://www.vulncheck.com/advisories/bitwarden-server-audit-log-injection-via-post-collect



