PT-2026-50738 · Zitadel · Zitadel
CVE-2026-55669
·
Published
2026-06-18
·
Updated
2026-07-30
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ZITADEL versions 4.0.0 through 4.11.0
ZITADEL versions 3.0.0 through 3.4.11
Description
An authentication bypass exists in the external JWT Identity Provider (IdP) implementation. While the system validates the cryptographic signature and the issuer (
iss) of JSON Web Tokens (JWTs), it fails to validate the audience (aud) claim. This allows a legitimate user of a separate service that shares the same trusted enterprise Identity Provider to use a token intended for that other service to authenticate to ZITADEL without authorization.Recommendations
Upgrade ZITADEL versions 4.0.0 through 4.11.0 to version 4.15.2 or later.
Upgrade ZITADEL versions 3.0.0 through 3.4.11 to version 3.4.12 or later.
Configure the external Identity Provider to issue scoped tokens with unique, non-overlapping audience values.
Deploy a reverse proxy, API gateway, or Web Application Firewall (WAF) to drop requests where the
aud field does not match the ZITADEL deployment target.Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zitadel