JSON Injection Vulnerability in Bitwarden Server from Bitwarden
CVE-2026-57522
Key Information:
Badges
What is CVE-2026-57522?
Bitwarden Server versions prior to 2026.5.0 are susceptible to a JSON injection vulnerability in the IntegrationTemplateProcessor.ReplaceTokens() method. This flaw allows authenticated users to introduce JSON metacharacters into event integration templates, specifically tokens that are derived from user-controlled fields such as display names. As a result, it is possible for malicious users to inject arbitrary key-value pairs into the payloads sent to external services like webhooks, SIEM, Slack, Teams, or Datadog. This makes it difficult to distinguish between legitimate data and any injected content, posing a significant risk to the integrity and security of the information being transmitted.
Affected Version(s)
server 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
