PT-2026-50739 · Zitadel · Zitadel
CVE-2026-55670
·
Published
2026-06-18
·
Updated
2026-07-30
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ZITADEL versions 4.0.0 through 4.15.1
ZITADEL versions 3.0.0 through 3.4.11
Description
A flaw in user lifecycle enforcement allows deleted users to retain their original organization or tenant association. When a user is deleted, the historical mapping of the resource owner within the event store's validation layer is not cleared. If a new user is subsequently provisioned in a different organization using the same ID, the event store validation logic matches the history to the original organization and routes the new user's events there. This results in a multi-tenancy isolation anomaly where an administrator from the original organization inadvertently gains full access to the new user record.
Recommendations
Upgrade to version 4.15.2 or later for versions 4.0.0 through 4.15.1.
Update to version 4.15.2 or later for versions 3.0.0 through 3.4.11.
Exploit
Fix
IDOR
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zitadel