PT-2026-50738 · Zitadel · Zitadel

CVE-2026-55669

·

Published

2026-06-18

·

Updated

2026-07-30

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 4.0.0 through 4.11.0 ZITADEL versions 3.0.0 through 3.4.11
Description An authentication bypass exists in the external JWT Identity Provider (IdP) implementation. While the system validates the cryptographic signature and the issuer (iss) of JSON Web Tokens (JWTs), it fails to validate the audience (aud) claim. This allows a legitimate user of a separate service that shares the same trusted enterprise Identity Provider to use a token intended for that other service to authenticate to ZITADEL without authorization.
Recommendations Upgrade ZITADEL versions 4.0.0 through 4.11.0 to version 4.15.2 or later. Upgrade ZITADEL versions 3.0.0 through 3.4.11 to version 3.4.12 or later. Configure the external Identity Provider to issue scoped tokens with unique, non-overlapping audience values. Deploy a reverse proxy, API gateway, or Web Application Firewall (WAF) to drop requests where the aud field does not match the ZITADEL deployment target.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55669
GHSA-G5H5-M4HM-XJRR
GO-2026-5391
OPENSUSE-SU-2026:21483-1

Affected Products

Zitadel