Junglewise Threat Intelligence

CVE-2026-57521: Bitwarden Server broken access control in PreviewInvoiceController

CVE-2026-57521 · Severity: medium · CVSS 4.3 · Published 2026-06-25

Technologies: Bitwarden Server.

Executive brief

Bitwarden Server is the backend infrastructure for the Bitwarden password management service. A security flaw in the server's billing component allowed any logged-in user to view sensitive financial information belonging to other organizations. An attacker could have accessed details such as subscription status, tax totals, and billing data, potentially leading to the exposure of corporate customer information and financial metadata.

Technical details

A broken access control vulnerability (IDOR) exists in the PreviewInvoiceController endpoints of Bitwarden Server. The affected endpoints, specifically POST .../subscription/plan-change and PUT .../subscription/update, utilized the [InjectOrganization] action filter to load organization data from the route but failed to implement the ManageOrganizationBillingRequirement authorization check. This allowed any authenticated user to supply an arbitrary organizationId and retrieve Stripe-computed tax totals, subscription status, and billing details belonging to other organizations. The vulnerability was addressed in version 2026.5.0 by adding the missing [Authorize<ManageOrganizationBillingRequirement>] attribute to the affected endpoints.

Affected products

  • Bitwarden Server before 2026.5.0

Timeline

  • 2026-05-05: patched: Authorization fix committed to server repository
  • 2026-05-29: advisory: Version 2026.5.0 released
  • 2026-06-25: disclosed: CVE-2026-57521 published

References