Junglewise Threat Intelligence

CVE-2026-57522: Bitwarden Server JSON injection in IntegrationTemplateProcessor

CVE-2026-57522 · Severity: low · CVSS 3.5 · Published 2026-06-25

Technologies: Bitwarden Server.

Executive brief

Bitwarden Server, the backend for the Bitwarden password manager, contained a flaw in how it processed event notifications for integrations like Slack, Teams, and SIEM platforms. An authenticated organization member could change their display name to include special characters that trick the system into inserting fake data into these notifications. While this could be used to spoof security logs or alerts, the risk was limited because the affected feature was not fully enabled in production environments at the time of discovery.

Technical details

A JSON injection vulnerability exists in `IntegrationTemplateProcessor.ReplaceTokens()` within Bitwarden Server. The component substitutes user-controlled tokens (such as `#ActingUserName#` or `#UserName#`) into event-integration templates using raw string concatenation without proper JSON encoding. An authenticated attacker can set their display name to include JSON metacharacters (e.g., `","injected_key":"value"`) to inject arbitrary key-value pairs into payloads delivered to webhooks, SIEMs, Slack, Teams, or Datadog. This allows attackers to spoof log entries or manipulate the structure of security events. The vulnerability was considered latent at the time of discovery as the integration feature was not yet fully exposed in the product. The issue is fixed in version 2026.5.0 by ensuring values are properly serialized.

Affected products

  • Bitwarden Server before 2026.5.0

Timeline

  • 2026-05-12: patched: Fix merged into main branch via PR 7593
  • 2026-05-29: advisory: Fixed in server release v2026.5.0
  • 2026-06-25: disclosed: NVD publication date

References