PT-2026-50739 · Zitadel · Zitadel

CVE-2026-55670

·

Published

2026-06-18

·

Updated

2026-07-30

CVSS v4.0

2.3

Low

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 4.0.0 through 4.15.1 ZITADEL versions 3.0.0 through 3.4.11
Description A flaw in user lifecycle enforcement allows deleted users to retain their original organization or tenant association. When a user is deleted, the historical mapping of the resource owner within the event store's validation layer is not cleared. If a new user is subsequently provisioned in a different organization using the same ID, the event store validation logic matches the history to the original organization and routes the new user's events there. This results in a multi-tenancy isolation anomaly where an administrator from the original organization inadvertently gains full access to the new user record.
Recommendations Upgrade to version 4.15.2 or later for versions 4.0.0 through 4.15.1. Update to version 4.15.2 or later for versions 3.0.0 through 3.4.11.

Exploit

Fix

IDOR

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55670
GHSA-6X8V-2FQ5-2229
GO-2026-5197
OPENSUSE-SU-2026:21483-1

Affected Products

Zitadel