Executive brief
Bitwarden Server's audit log endpoint failed to verify that users belonged to an organization before recording events in that organization's log. This allowed any authenticated user to inject forged, backdated audit entries into any organization's audit log—a falsification of security records that could obscure actual unauthorized activity or be used for compliance fraud.
Technical details
The POST /collect audit logging endpoint accepted four organization event types (Organization_ClientExportedVault, Organization_AutoConfirmEnabled_Admin, Organization_AutoConfirmDisabled_Admin, Organization_InviteLinkClientCopied) without verifying the caller's membership in the target organization. An authenticated user could supply an arbitrary organization ID in the request body and the endpoint would load that organization and log the event without membership checks, allowing injection of backdated entries. The fix adds a GetByOrganizationAsync(organizationId, userId) membership guard that silently drops events from non-members while preserving normal logging for legitimate organization members.
Affected products
- Bitwarden Server before 2026.7.2
Timeline
- 2026-08-10: disclosed
- 2026-07-13: patched: Fix merged in commit 2aa92a3c, version 2026.7.2